Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2004-0490
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2004-0490

Description:
cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/16239

MISC
  http://bugzilla.cpanel.net/show_bug.cgi?id=283
  http://www.securiteam.com/tools/5TP0N15CUA.html
  http://www.a-squad.com/audit/explain10.html

CONFIRM
  http://bugzilla.cpanel.net/show_bug.cgi?id=664

BUGTRAQ
  http://www.securityfocus.com/archive/1/364112

BID
  10407


Return to the previous page.