Описание
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
Ссылки
- Mailing List
- Mailing List
- Broken LinkExploitPatchVendor Advisory
- Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
- Mailing List
- Mailing List
- Broken LinkExploitPatchVendor Advisory
- Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- Broken LinkExploitPatchThird Party AdvisoryVDB EntryVendor Advisory
- Third Party AdvisoryVDB Entry
- Third Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:cpanel:cpanel:9.4.1:*:*:*:*:*:*:*
EPSS
Процентиль: 32%
0.00122
Низкий
5.5 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-59
Связанные уязвимости
CVSS3: 5.5
github
почти 4 года назад
cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files via the .htaccess file when Front Page extensions are enabled or disabled.
EPSS
Процентиль: 32%
0.00122
Низкий
5.5 Medium
CVSS3
5 Medium
CVSS2
Дефекты
CWE-59