CVE-2004-1770
cPanel 9.1.0 - Remote Code Execution via Login Page User Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2004-1770. PoCs published by Arab VieruZ.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in cPanel's login script due to insufficient input sanitization. An attacker can execute arbitrary commands by embedding shell metacharacters in the 'user' parameter of the login URI.
Description
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.
Exploits (1)
This exploit demonstrates a command injection vulnerability in cPanel's login script due to insufficient input sanitization. An attacker can execute arbitrary commands by embedding shell metacharacters in the 'user' parameter of the login URI.