Mar 15, 2004 : Flaw Found in cPanel's WebHost Manager


📅 - According to an advisory posted in SecurityFocus, a vulnerability has been discovered in cPanel's (cpanel.net) WebHost Manager reseller control panel that may be exploited by malicious users, allowing them to run some commands as the root (superuser).

The advistory said the vulnerability affects a function in WebHost Manager that allows resellers to send lost and forgotten passwords by email. The setting is found in the "Tweak Settings Section." According to the advisory, "This hole is built in to all compiled cPanel binaries and as such cannot be 'patched.' Security Focus recommends that users disable the feature.
The cPanel solution is deployed on approximately 1.4 million hostnames worldwide and is popular with large Web hosting companies running dedicated servers. According to the advisory, the flaw affects all versions up to 9.1.0 build 34 with all later versions having been repaired.
CPanel is developed by Scranton, Pennsylvania-based DarkOrb Communications.

Reads: 1820 | Category: General | Source: TheWHIR : Web Host Industry Reviews
URL source: http://www.thewhir.com/marketwatch/cpa031504.cfm
Want to add a website news or press release ? Just do it, it's free! Use add web hosting news!