Please read this topic:
http://forums.cpanel.net/f7/security-issue-123005.html
Search before open a topic (double) and when you have find a bug don't post it in a public forum contact cPanel true a ticket to inform them. It's all for yours and ours security.