CVE-2004-0529

Current Description

The modified suexec program in cPanel, when configured for mod_php and compiled for Apache 1.3.31 and earlier without mod_phpsuexec, allows local users to execute untrusted shared scripts and gain privileges, as demonstrated using untainted scripts such as (1) proftpdvhosts or (2) addalink.cgi, a different vulnerability than CVE-2004-0490.

Referenced by CVEs:CVE-2004-0490

Basic Data

PublishedAugust 06, 2004
Last ModifiedJuly 11, 2017
Assignercve@mitre.org
Data TypeCVE
Data FormatMITRE
Data Version4.0
Problem TypeNVD-CWE-Other
CVE Data Version4.0

Base Metric V2

CVSS 2 - Version2.0
CVSS 2 - Vector StringAV:L/AC:L/Au:N/C:C/I:C/A:C
CVSS 2 - Access VectorLOCAL
CVSS 2 - Access ComplexityLOW
CVSS 2 - AuthenticationNONE
CVSS 2 - Confidentiality ImpactCOMPLETE
CVSS 2 - Availability ImpactCOMPLETE
CVSS 2 - Base Score7.2
SeverityHIGH
Exploitability Score3.9
Impact Score10.0
Obtain All Privilegetrue
Obtain User Privilegefalse
Obtain Other Privilegefalse

Base Metric V3

No data provided.

Configurations

  • OR - Configuration 1
    Cpe VersionPartVendorProductVersionUpdateEditionLanguageSW EditionTarget SWTarget HWOtherVersion Start IncludingVersion End IncludingVersion Start ExcludingVersion End Excluding
    2.3ApplicationCluecentralSuexec.patch********

Vulnerable Software List

VendorProductVersions
Cluecentral Suexec.patch *

References

NameSourceURLTags
http://bugzilla.cpanel.net/show_bug.cgi?id=668http://bugzilla.cpanel.net/show_bug.cgi?id=668CONFIRM
20040605 cPanel mod_php suEXEC Taint Vulnerabilityhttp://marc.info/?l=bugtraq&m=108663003608211&w=2BUGTRAQ
11798http://secunia.com/advisories/11798SECUNIA
1010411http://securitytracker.com/id?1010411SECTRACK
10478http://www.securityfocus.com/bid/10478BIDVendor Advisory
cpanel-suexec-command-execute(16347)https://exchange.xforce.ibmcloud.com/vulnerabilities/16347XF