Topic: Possible SQL exploit in Vcpanel [SOLVED]
Hi,
Please respond urgently to the following
One of my clients has discovery the following exploit that we think would allow someone to reset any vps' root password, if he have a vcPanel account .
John
Empowering Technology Innovations
You are not logged in. Please login or register.
Linux Server Management | Web Hosting Support | Outsourced Spport | Enterprise Cluster Administration | Software Development by Syslint Technologies → Bug Reports → Possible SQL exploit in Vcpanel [SOLVED]
Hi,
Please respond urgently to the following
One of my clients has discovery the following exploit that we think would allow someone to reset any vps' root password, if he have a vcPanel account .
John
Hello,
This is fixed and updated the distribution files too. So it is replaced from the downloads of today Aug 7 th 2010 . All other previous installations are requested to do the fix as follows,
----------
This bug is fixed . Please download the updated file from http://download.vcpanel.net/updates/file122.php.zip and extract it , then copy to /usr/local/vcpanel/htdocs/vclient/treeview/
Steps :
# wget -c http://download.vcpanel.net/updates/file122.php.zip
# unzip file122.php.zip
# chown vcpanel.vcpanel file122.php
# cp -f file122.php /usr/local/vcpanel/htdocs/vclient/treeview/
Linux Server Management | Web Hosting Support | Outsourced Spport | Enterprise Cluster Administration | Software Development by Syslint Technologies → Bug Reports → Possible SQL exploit in Vcpanel [SOLVED]
Powered by PunBB, supported by Informer Technologies, Inc.
Currently installed 2 official extensions. Copyright © 2003–2009 PunBB.