#1 (permalink)  
Old 06-29-2009, 04:57 PM
Registered User
 
Join Date: Aug 2005
Location: /dev/null
Posts: 38
omenix is on a distinguished road
Security issue

Hello guys,

First of all I'm not sure whether this is the right section to post or not. Please move it somewhere else if needed.. someone has found a vulnerability @ /frontend/x3/stats/lastvisit.html?domain= (Directory traversal) but username/password is required. I hope you guys can release an update as soon as possible for this vulnerability. Thanks.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #2 (permalink)  
Old 06-29-2009, 05:17 PM
Registered User
 
Join Date: Sep 2004
Posts: 792
mtindor is on a distinguished road
Quote:
Originally Posted by omenix View Post
Hello guys,

First of all I'm not sure whether this is the right section to post or not. Please move it somewhere else if needed.. someone has found a vulnerability @ /frontend/x3/stats/lastvisit.html?domain= (Directory traversal) but username/password is required. I hope you guys can release an update as soon as possible for this vulnerability. Thanks.
I'd suggest / ask that you open a ticket with Cpanel at http://tickets.cpanel.net, providing every bit of information you know about said "vulnerability." That would help everyone out.

Thanks!

Mike
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 06-29-2009, 05:39 PM
cPanelDavidG's Avatar
cPanel Technical Sales
 
Join Date: Nov 2006
Location: Houston, TX
Posts: 7,995
cPanelDavidG is on a distinguished road
Quote:
Originally Posted by omenix View Post
Hello guys,

First of all I'm not sure whether this is the right section to post or not. Please move it somewhere else if needed.. someone has found a vulnerability @ /frontend/x3/stats/lastvisit.html?domain= (Directory traversal) but username/password is required. I hope you guys can release an update as soon as possible for this vulnerability. Thanks.
Please email security@cpanel.net with any details you can provide regarding replicating this issue etc.
__________________
Want our technical analysts to login to your server to assist you? You can contact our technical analysts at: http://tickets.cPanel.net/submit
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 06-29-2009, 06:31 PM
Registered User
 
Join Date: Aug 2005
Location: /dev/null
Posts: 38
omenix is on a distinguished road
Thanks. Report has already sent.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 06-30-2009, 04:02 PM
Registered User
 
Join Date: Mar 2004
Posts: 13
ehsanix
Any response from Cpanel ?!
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 06-30-2009, 08:36 PM
Registered User
 
Join Date: Mar 2003
Posts: 205
flashweb
Cpanel (lastvisit.html domain) Arbitrary File Disclosure Vuln (auth)

I run upcp, it still not fixed.
__________________
HostOnNet.com
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 06-30-2009, 10:08 PM
konrath's Avatar
Registered User
 
Join Date: May 2005
Location: Brasil
Posts: 208
konrath is on a distinguished road
Quote:
Originally Posted by flashweb View Post

Hello

This bug did not work with me.

cPanel 11.24.4-S36281 - WHM 11.24.2 - X 3.9
REDHAT Enterprise 3 i686 standard on server

Thank you
Konrath

Last edited by konrath; 06-30-2009 at 10:20 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 07-01-2009, 02:21 AM
Registered User
 
Join Date: Mar 2004
Posts: 13
ehsanix
I am using (RELEASE tree) : cPanel 11.24.4-R36167 - WHM 11.24.2 - X 3.9

we have this problem. do you think I should use Stable tree instead ?
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #9 (permalink)  
Old 07-01-2009, 09:39 AM
cpanelkenneth's Avatar
cPanel Quality Assurance
 
Join Date: Apr 2006
Posts: 3,222
cpanelkenneth is on a distinguished road
This vulnerability is fixed in EDGE 36912+ and CURRENT 36913+. RELEASE and STABLE will be published soon with the same fix.

The vulnerability allows an authenticated user to view any file he has permission to access. An intrepid user can accomplish something similar by using a CGI or PHP script via Apache. No privilege escalation is involved, hence access to restricted files, such as /etc/shadow, is not possible.
__________________
cPanel Kenneth
cPanel QA
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #10 (permalink)  
Old 07-01-2009, 02:25 PM
nicosoft's Avatar
Registered User
 
Join Date: Oct 2008
Posts: 10
nicosoft is on a distinguished road
Quote:
Originally Posted by cpanelkenneth View Post
This vulnerability is fixed in EDGE 36912+ and CURRENT 36913+. RELEASE and STABLE will be published soon with the same fix.

The vulnerability allows an authenticated user to view any file he has permission to access. An intrepid user can accomplish something similar by using a CGI or PHP script via Apache. No privilege escalation is involved, hence access to restricted files, such as /etc/shadow, is not possible.
Nice Info, Sir. But Before the RELEASE and STABLE already fix. I have to disable Latest Visitor in the Feature Manager on WHM. Thus, the hole is Minimize. Thank You.
__________________
Nicosoft Media
YOUR ONE STOP & RELIABLE HOST
Hosting, Reseller, VPS and Dedicated Server Provider

http://www.nicosoftmedia.com/
YM:nicosoftmedia
+62.8127859462

Last edited by nicosoft; 07-01-2009 at 02:28 PM.
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #11 (permalink)  
Old 07-04-2009, 07:46 AM
d_t d_t is online now
Registered User
 
Join Date: Sep 2003
Location: Bucharest
Posts: 163
d_t is on a distinguished road
Quote:
Originally Posted by cpanelkenneth View Post
An intrepid user can accomplish something similar by using a CGI or PHP script via Apache.
Actually, open_basedir prevent this for mod_php. But indeed, can be done from CGI.

Please let us know when the new release will be available (latest is cPanel 11.24.4-R36167 and has the bug).
__________________
Joomla & Magento cPAddons
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Security Issue... tAzMaNiAc cPanel and WHM Discussions 13 04-20-2007 02:37 PM
Security Issue kgordon cPanel and WHM Discussions 3 06-19-2004 09:26 PM
security issue griz cPanel and WHM Discussions 0 07-17-2003 04:49 PM
security issue shann cPanel and WHM Discussions 7 06-06-2003 07:41 PM
security issue NNNils cPanel and WHM Discussions 16 04-28-2003 03:55 AM


All times are GMT -5. The time now is 06:40 AM.


Powered by vBulletin® Version 3.8.2
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
© cPanel Inc