CVE-2004-1421

WHM AutoPilot <2.4.6.5 - RCE

Title source: llm

Description

Multiple PHP remote file inclusion vulnerabilities (1) step_one.php, (2) step_one_tables.php, (3) step_two_tables.php in WHM AutoPilot 2.4.6.5 and earlier allow remote attackers to execute arbitrary PHP code by modifying the server_inc parameter to reference a URL on a remote web server that contains the code.

Exploits (1)

exploitdb WRITEUP
webappsphp
https://www.exploit-db.com/exploits/43818

Scores

EPSS 0.0765
EPSS Percentile 91.9%

Details

Status published
Products (3)
whm/whm_autopilot 2.4.5
whm/whm_autopilot 2.4.6
whm/whm_autopilot 2.4.6.5
Published Dec 31, 2004
Tracked Since Feb 18, 2026