PDA

View Full Version : cPanel Password Change Privilege Escalation Security Issue


elix
08-16-2005, 10:22 AM
:eek: Just another reason to keep strong root passwords...

http://secunia.com/advisories/16362/

Best,

elix

Hvu
08-16-2005, 01:17 PM
;P Directadmin yo`

Tony
08-18-2005, 08:24 AM
Solution:
Use a strong root password.

That's probably the best advice.

The `vulnerability' has been around since 9.x.

I use it as a handy feature on my main account so I can bounce through cPanel and check stats for all the sites.

Tony
08-18-2005, 08:32 AM
I should also probably mention, that this is part of the built in root override function.

There isn't actually any vulnerability there, and it won't get 'patched/fixed' etc in any forthcoming version of cPanel. =)