CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.0. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CVE
CVE-2004-1604
Severity
MEDIUM
CVSS
5
EPSS
1.05%
Original NVD Description
cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled.