Back

CVE-2004-0490

cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529.

Published: Aug 18, 2004 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (13)

Vendor Product Version
cpanel cpanel 5.0
cpanel cpanel 5.3
cpanel cpanel 6.0
cpanel cpanel 6.2
cpanel cpanel 6.4
cpanel cpanel 6.4.1
cpanel cpanel 6.4.2
cpanel cpanel 6.4.2_stable_48
cpanel cpanel 7.0
cpanel cpanel 8.0
cpanel cpanel 9.0
cpanel cpanel 9.1
cpanel cpanel 9.1.0_r85

GitHub Security Advisory GHSA-xw7p-mxv9-wcvh

cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the -...

Risk Scores

CVSS Score 7.2 / 10
EPSS Score 4.47%

Top 9% most likely to be exploited

Threat Score 30.1 / 100

Data Sources

NVD EPSS GitHub