Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:11342
HistoryFeb 08, 2006 - 12:00 a.m.

[Full-disclosure] Cpanel Admin login (username) Disclosure

2006-02-0800:00:00
vulners.com
24

Hi, could somebody kindly confirm this.
When a null username and a null password is provided in the cpanel administration, port 2082, (basic authorization prompt) and then cancelling the prompt the second time, the webpage presents a hyperlink to reset the password which contains valid username for the cpanel administration.
Thanks
Sumit

Sumit Siddharth