20040311 cPanel Secuirty Advisory CPANEL-2004:01-01mailing list
http://marc.info/?l=bugtraq&m=107904890724201&w=2 CVE-2004-1769
cPanel 5/6/7/8/9 - Resetpass Remote Command Execution
Record summary
CVE-2004-1769 has a selected CVSS score of 10.0; EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBcPanel 5/6/7/8/9 - Resetpass Remote Command ExecutionExploitDB exploitby Arab VieruZNot analyzed1 file
Repository PoCs
GitHubsinkaroid/shigureshRepository PoCby sinkaroidStars: 2Not analyzed4 files
References
711111Third-party advisory
http://secunia.com/advisories/11111 VU#831534Third-party advisory
http://www.kb.cert.org/vuls/id/831534 20040311 Cpanel 8.*.* have a problem ?mailing list
http://www.securityfocus.com/archive/1/357064/2004-03-08/2004-03-14/0 9848vdb entry
http://www.securityfocus.com/bid/9848 cpanel-resetpass-execute-commands(15443)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/15443 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1769