Community Forums
Connect with us on LinkedIn
Community Notice
+ Reply to Thread
Results 1 to 11 of 11
  1. #1
    Member
    Join Date
    Aug 2005
    Location
    /dev/null
    Posts
    38

    Default Security issue

    Hello guys,

    First of all I'm not sure whether this is the right section to post or not. Please move it somewhere else if needed.. someone has found a vulnerability @ /frontend/x3/stats/lastvisit.html?domain= (Directory traversal) but username/password is required. I hope you guys can release an update as soon as possible for this vulnerability. Thanks.

  2. #2
    Member
    Join Date
    Sep 2004
    Posts
    887

    Default

    Quote Originally Posted by omenix View Post
    Hello guys,

    First of all I'm not sure whether this is the right section to post or not. Please move it somewhere else if needed.. someone has found a vulnerability @ /frontend/x3/stats/lastvisit.html?domain= (Directory traversal) but username/password is required. I hope you guys can release an update as soon as possible for this vulnerability. Thanks.
    I'd suggest / ask that you open a ticket with Cpanel at http://tickets.cpanel.net, providing every bit of information you know about said "vulnerability." That would help everyone out.

    Thanks!

    Mike

  3. #3
    Technical Product Specialist cPanelDavidG's Avatar
    Join Date
    Nov 2006
    Location
    Houston, TX
    Posts
    10,718
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    Quote Originally Posted by omenix View Post
    Hello guys,

    First of all I'm not sure whether this is the right section to post or not. Please move it somewhere else if needed.. someone has found a vulnerability @ /frontend/x3/stats/lastvisit.html?domain= (Directory traversal) but username/password is required. I hope you guys can release an update as soon as possible for this vulnerability. Thanks.
    Please email security@cpanel.net with any details you can provide regarding replicating this issue etc.

  4. #4
    Member
    Join Date
    Aug 2005
    Location
    /dev/null
    Posts
    38

    Default

    Thanks. Report has already sent.

  5. #5
    Member
    Join Date
    Mar 2004
    Posts
    13

    Default

    Any response from Cpanel ?!

  6. #6
    Member
    Join Date
    Mar 2003
    Posts
    222
    cPanel/Enkompass Access Level

    Root Administrator

  7. #7
    Member konrath's Avatar
    Join Date
    May 2005
    Location
    Brasil
    Posts
    312

    Default

    Quote Originally Posted by flashweb View Post

    Hello

    This bug did not work with me.

    cPanel 11.24.4-S36281 - WHM 11.24.2 - X 3.9
    REDHAT Enterprise 3 i686 standard on server

    Thank you
    Konrath
    Last edited by konrath; 06-30-2009 at 10:20 PM.

  8. #8
    Member
    Join Date
    Mar 2004
    Posts
    13

    Default

    I am using (RELEASE tree) : cPanel 11.24.4-R36167 - WHM 11.24.2 - X 3.9

    we have this problem. do you think I should use Stable tree instead ?

  9. #9
    cPanel Development cpanelkenneth's Avatar
    Join Date
    Apr 2006
    Posts
    3,768
    cPanel/Enkompass Access Level

    Root Administrator

    Default

    This vulnerability is fixed in EDGE 36912+ and CURRENT 36913+. RELEASE and STABLE will be published soon with the same fix.

    The vulnerability allows an authenticated user to view any file he has permission to access. An intrepid user can accomplish something similar by using a CGI or PHP script via Apache. No privilege escalation is involved, hence access to restricted files, such as /etc/shadow, is not possible.
    Kenneth
    Product Development
    cPanel, Inc.

  10. #10
    Member nicosoft's Avatar
    Join Date
    Oct 2008
    Posts
    10

    Default

    Quote Originally Posted by cpanelkenneth View Post
    This vulnerability is fixed in EDGE 36912+ and CURRENT 36913+. RELEASE and STABLE will be published soon with the same fix.

    The vulnerability allows an authenticated user to view any file he has permission to access. An intrepid user can accomplish something similar by using a CGI or PHP script via Apache. No privilege escalation is involved, hence access to restricted files, such as /etc/shadow, is not possible.
    Nice Info, Sir. But Before the RELEASE and STABLE already fix. I have to disable Latest Visitor in the Feature Manager on WHM. Thus, the hole is Minimize. Thank You.
    Last edited by nicosoft; 07-01-2009 at 02:28 PM.
    Nicosoft Media
    YOUR ONE STOP & RELIABLE HOST
    Hosting, Reseller, VPS and Dedicated Server Provider

    http://www.nicosoftmedia.com/
    YM:nicosoftmedia
    +62.8127859462

  11. #11
    d_t
    d_t is offline
    Member
    Join Date
    Sep 2003
    Location
    Bucharest
    Posts
    231

    Default

    Quote Originally Posted by cpanelkenneth View Post
    An intrepid user can accomplish something similar by using a CGI or PHP script via Apache.
    Actually, open_basedir prevent this for mod_php. But indeed, can be done from CGI.

    Please let us know when the new release will be available (latest is cPanel 11.24.4-R36167 and has the bug).

Similar Threads & Tags
Similar threads

  1. Security issue?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 04-21-2008, 08:12 AM
  2. Is this a security issue?
    By BianchiDude in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 07-18-2006, 04:04 PM
  3. Security issue
    By prof in forum Security
    Replies: 3
    Last Post: 02-21-2006, 12:31 PM
  4. Possible security issue
    By GordonH in forum cPanel and WHM Discussions
    Replies: 0
    Last Post: 01-27-2004, 05:38 AM
  5. security issue
    By NNNils in forum cPanel and WHM Discussions
    Replies: 16
    Last Post: 04-28-2003, 03:55 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube