Web Hosting Talk







View Full Version : Cpanel current exploit.


Serverman
02-26-2003, 07:34 PM
I'm not going to say what it is for those of you that don't know because it would be hell. However someone I know told me about it and it allows you to run any command as user Cpanel through any website on a Cpanel server.

Does anyone know if they have done anything about it yet? We have removed this certain script from all of our servers.

phactor
02-26-2003, 07:38 PM
hm.. u could say wich script is.. otherwise we all are vulnerable?!? :(

FHDave
02-26-2003, 07:38 PM
You mean these vulnerabilities?

http://webhostingtalk.com/showthread.php?s=&threadid=114752

That's quite old :)

phactor
02-26-2003, 07:42 PM
ahhh

that's old :)

btw.. anyone here knows when php4.3.1 will be available for cpanel?

Serverman
02-26-2003, 07:43 PM
Yes, that's it. Our reports are that they haven't removed it yet.

MBC
02-26-2003, 07:53 PM
All fixes have been made and are in the changelog at cPanel.