Family: CGI abuses --> Category: infos
cPanel FrontPage Extension Flaws Vulnerability Scan
Vulnerability Scan Summary
Checks for the version of cpanel
Detailed Explanation for this Vulnerability Test
The remote host is running a version of cpanel which is older or as
old as version 9.9.1.
The remote version of this software is vulnerable to two flaws :
- An information disclosure flaw if the FrontPage Extension is installed,
which may allow a local attacker to read arbitrary files on the remote host
with the rights of the 'cpsvrd' process.
- A file ownership problem in the FrontPage Extension which may allow a local
attacker to read the content of a .htaccess file
Solution : Upgrade to the newest version of cPanel or disable this service
Threat Level: Medium
Click HERE for more information and discussions on this network vulnerability scan.