Book Mark

Ike.ninja

Linux Fun
  • Home
  • How to
  • Reference Links
  • Categories
    • Releases
    • Plesk
    • Community
    • CMS
    • security
    • MYSQL
    • cPanel
  • Tools
    • IP Checker
    • Byte Converter
RSS

cPanel Protects Against PHP Vulnerability

May08
by Ike on May 8, 2012 at 5:39 pm
Posted In: Apache, CMS, Community, cPanel, Events, Releases, security, System

cPanel & WHM servers using the default cPanel PHP CGI configuration are not vulnerable to the command line switch vulnerability.

A recently disclosed flaw in PHP’s CGI implementation allows malicious users to remotely view and execute source code. The exploit was documented by the Eindbazen team and documented as CVE-2012-1823.

cPanel & WHM servers are not affected by this, thanks in part to a wrapper script used by cPanel & WHM when Apache is configured to use CGI for the PHP handler. This wrapper script does not pass through any command line options.

Server administrators are encouraged to verify their PHP configuration.

When configured to use CGI or FCGI, cPanel & WHM instructs Apache to use the following wrapper script /usr/local/cpanel/cgi-sys/php5 or /usr/local/cpanel/cgi-sys/php4 (The number after “php” is based upon the current major version of PHP.) The unmodified version of the wrapper script looks like the following:

<p>#!/bin/sh</p> <p># If you customize the contents of this wrapper script, place&nbsp;</p><p># a copy at /var/cpanel/conf/apache/wrappers/php$php_version&nbsp;</p><p># so that it will be reinstalled when Apache is updated or the&nbsp;</p><p># PHP handler configuration is changed</p> <p>exec $binary</p>

The $binary placeholder will contain /usr/bin/php or /usr/php4/bin/php By default, no command line parameters are included.

Read CVE-2012-1823

└ Tags: Apache, command, PHP
 Comment 

MySQL :: MySQL Users Conference & Expo 2004 Highlights

May06
by Ike on May 6, 2012 at 3:39 pm
Posted In: Community, MYSQL, Releases

Skip navigation links Il database open source più diffuso al mondo Contatta un rappresentante MySQL Login | Registrazione MySQL.it Download (GA) Home Prodotti

└ Tags: open source
 Comment 

Parallels Plesk 10.4.4 MU#29

May05
by Ike on May 5, 2012 at 8:22 am
Posted In: Plesk, Releases

The following bug have been fixed:
[-] Slow creating of configuration backup because APS creation utility is executed for each subscription.
[-] Client CLI is failed to create client with email used as login by existed hosting user.

└ Tags: APS, backup, Parallels Plesk
 Comment 

Parallels Plesk 9.5.5 MU#1

May03
by Ike on May 3, 2012 at 1:07 pm
Posted In: Plesk, Releases

[+] BIND version has been upgraded to 9.8.1-P1, that also fixes CVE-2011-4313 not exploitable in Plesk configurations. (90473)

The following bug have been fixed:
[-] Incorporated Plesk Panel security fix from the update http://kb.parallels.com/en/113321 (106355)
[-] Automatic key update failures aren’t logged (105476)
[-] XSS vulnerability in Horde IMP has been fixed (CVE-2012-0791) (105744)
[-] Minor security vulnerability in Plesk Panel has been addressed

└ Tags: CVE, Parallels Plesk, update
 Comment 

Microupdates supporting for Parallels Plesk 9.5.5 has been added

May03
by Ike on May 3, 2012 at 1:06 pm
Posted In: Plesk, Releases

Plesk Service Team is glad to inform you that we have implement supporting of Micro-updates technology for Plesk 9.5.5 for Windows.
Please, check http://kb.parallels.com/en/113809 for more details.

└ Tags: Parallels Plesk, Plesk Service Team
 Comment 
  • Page 2,890 of 2,982
  • « First
  • «
  • 2,888
  • 2,889
  • 2,890
  • 2,891
  • 2,892
  • »
  • Last »

What’s New?

  • Fedora 42: uriparser CVE-2025-67899 Fix for Unbounded Recursion Issue
  • Fedora 42: util-linux Critical Buffer Overflow CVE-2025-14104 Advisory
  • Fedora 42: mqttcli Update 0.2.8 Critical Integer Overflow Issues
  • Fedora 42: Chromium High CVE-2025-14765 Out of Bounds Security Risks
  • Debian: Roundcube Important XSS and Information Leak Fix DSA-6087-1
  • Debian: MediaWiki DSA-6085-1 Security Updates for DoS and XSS
  • Debian: Urgent Vulnerability in Dropbear DSA-6086-1 CVE-2025-14282
  • Plesk 2025: A Year in Review
  • Ubuntu 24.04: Linux Xilinx Important Kernel Security Fix USN-7931-4
  • Ubuntu 22.04 LTS: Linux Kernel Critical Fix for Raspberry Pi USN-7928-4
  • Ubuntu 18.04 LTS – Oracle Kernel Critical Security Flaws USN-7922-3
  • Ubuntu 24.04: Advisory USN-7921-2 for Real-time Kernel CVE-2025-39946
  • Debian Trixie: c-ares Critical Denial of Service Advisory DSA-6084-1
  • Debian: webkit2gtk Important Memory Corruption Issues DSA-6083-1
  • Fedora 42: brotli 1.2.0 Critical DoS Fix FEDORA-2025-9e233a4e22
  • Fedora 42: perl-Alien-Brotli Faces Critical Denial-of-Service Risk
  • Fedora 42: CUPS Critical Local DoS Issue FEDORA-2025-c09b980696
  • Fedora 42: Security Advisory for golang-github-facebook-time CVE-2025-65637
  • Ubuntu 24.04: Linux Kernel Azure FIPS Critical Info Exposure CVE-2025-40300
  • Fedora 43: assimp Library Critical CVE-2025-11277 Update
  • Fedora 43: util-linux Update 2.41.4 Urgent CVE-2025-14105
  • Ubuntu 20.04 LTS: Linux-azure-fips Critical VMSCAPE Exposure CVE-2025-40300
  • Ubuntu 20.04: Linux-Azure Critical Info Leak CVE-2025-40300 USN-7939-1
  • Ubuntu 20.04 LTS: Important Security Update USN-7939-1 for CVE-2025-40300
  • Ubuntu 20.04: Linux Kernel Critical Info Disclosure CVE-2025-40300

Search

Translator

Tags

Business and industry code Community cPanel CVE Debian Debian Linux Distribution - Security Advisories Development Events Fedora Fedora Linux Distribution - Security Advisories General Hosting Important Advisory Linux Moderate Advisory Month in WordPress news Parallels Plesk Parallels Plesk Panel Performance PHP Plesk news and announcements Plesk Panel Podcast ProdDevSec Product and technology Products Project Release News Red Hat Red Hat Linux Distribution - Security Advisories Releases security Security Centre sensitive site Ubuntu Ubuntu Linux Distribution - Security Advisories update updates Various vulnerability Web Server Survey Wordpress wp-briefing

Posts

Helpful Links

  • Liquidweb.com
  • MYSQL Dev Documentation
  • Plugins
  • Source forge SED command
  • Themes
  • WordPress Documentation
  • You Tube
December 2025
M T W T F S S
« Nov    
1234567
891011121314
15161718192021
22232425262728
293031  
  • Google
  • Yahoo
  • Liquid Web
  • Storm
  • YouTube

©1999-2025 Ike.ninja | Powered by WordPress with Easel | Subscribe: RSS | Back to Top ↑

50 queries. 8.75 mb Memory usage. 0.267 seconds.