Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11304
HistoryFeb 05, 2006 - 12:00 a.m.

[Full-disclosure] cPanel 10 File Editing Vulnerability

2006-02-0500:00:00
vulners.com
12

In cPanel 10, the script "erredit.html," which is supposed to edit a specific set of files, can edit any file acessible by the cPanel.

Example:
http://www.example.com:2082/frontend/x/err/erredit.html?dir=public_html/&file=index.php