CVE-2003-1426 Information

Description

Openwebmail in cPanel 5.0 when run using suid Perl adds the directory in the SCRIPT_FILENAME environment variable to Perl’s @INC include array which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.

Reference

http://archives.neohapsis.com/archives/vulnwatch/2003-q1/0087.html http://www.securityfocus.com/bid/6885 https://exchange.xforce.ibmcloud.com/vulnerabilities/11357

Share on: