Vulnerabilities > CVE-2003-1426 - Configuration vulnerability in Cpanel 5.0
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Common Weakness Enumeration (CWE)
References
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0087.html
- http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0087.html
- http://www.securityfocus.com/bid/6885
- http://www.securityfocus.com/bid/6885
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11357
- https://exchange.xforce.ibmcloud.com/vulnerabilities/11357