PoC Index

CVE-2004-0490

HIGH 7.2EPSS 4.5%

cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.

CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
4.47% chance of exploitation in the next 30 days, 91th percentile
Published
2004-06-03
Updated
2024-08-08

ExploitDB entries (1)

References

Related