ZPanel <= 10.0.0.2 htpasswd Module Username Command Execution
Vulnerability Description
A remote command execution vulnerability exists in ZPanel version 10.0.0.2 in its htpasswd module. When creating .htaccess files, the inHTUsername field is passed unsanitized to a system() call that invokes the system’s htpasswd binary. By injecting shell metacharacters into the username field, an authenticated attacker can execute arbitrary system commands. Exploitation requires a valid ZPanel account—such as one in the default Users, Resellers, or Administrators groups—but no elevated privileges.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-10053
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- shachibista
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/unix/webapp/zpanel_username_exec.rb
- https://web.archive.org/web/20130617014355/http://forums.zpanelcp.com/showthread.php?27898-Serious-Remote-Execution-Exploit-in-Zpanel-10-0-0-2
- https://github.com/zpanel/zpanelx
- https://www.vulncheck.com/advisories/zpanel-htpasswd-module-username-command-execution
More from ZPanel Project
View All →Affected Vendor
ZPanel Project
View all reports →