← Back

CVE-2003-1426

nvd nist
Published: Dec 31, 2003Modified: Apr 16, 2026

JSON object

Loading...
3.3
Vector
AV:L/AC:M/Au:N/C:P/I:P/A:N
Exploitability: 3.4 / Impact: 4.9
Source: NVD

Description

Openwebmail in cPanel 5.0, when run using suid Perl, adds the directory in the SCRIPT_FILENAME environment variable to Perl's @INC include array, which allows local users to execute arbitrary code by modifying SCRIPT_FILENAME to reference a directory containing a malicious openwebmail-shared.pl executable.

Affected (1)

Products: Cpanel: Cpanel
1 product
Cpanel
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 5.0

Related CWEs

References (6)

Timeline

No history available yet.