cPanel Resetpass远程命令执行漏洞

漏洞信息详情

cPanel Resetpass远程命令执行漏洞

漏洞简介

cPanel 9.1.0 build 34以及之前包括8.x的版本中\”允许cPanel用户通过邮件重置密码\”的功能存在漏洞。远程攻击者借助resetpass的user参数执行任意代码。

漏洞公告

The vendor has released a fix to address this issue for customers using EDGE and CURRENT versions. The vendor has outlined that affected customers should perform the following to update their product:
Perform the following as root from the shell.
# /scripts/upcp
This should update the cPanel and WHM package to the latest version.

参考网址

来源:US-CERT Vulnerability Note: VU#831534
名称: VU#831534
链接:http://www.kb.cert.org/vuls/id/831534

来源: XF
名称: cpanel-resetpass-execute-commands(15443)
链接:http://xforce.iss.net/xforce/xfdb/15443

来源: BID
名称: 9848
链接:http://www.securityfocus.com/bid/9848

来源: BUGTRAQ
名称: 20040311 Cpanel 8.*.* have a problem ?
链接:http://www.securityfocus.com/archive/1/357064/2004-03-08/2004-03-14/0

来源: SECUNIA
名称: 11111
链接:http://secunia.com/advisories/11111

来源: BUGTRAQ
名称: 20040311 cPanel Secuirty Advisory CPANEL-2004:01-01
链接:http://marc.theaimsgroup.com/?l=bugtraq&m=107904890724201&w=2

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享