Navigation
  Secure Billing Login
Email Address:
Password:
cPanel Security Alert
March 7, 2008, 6:54 am

To our customers that are using cPanel, we received this alert:

An arbitrary file inclusion vulnerability has been discovered in the Horde
webmail application. At present, we can confirm that this security
vulnerability in question affects Horde 3.1.6 and earlier. Based on
incomplete information at this time, we also believe this affects Horde
Groupware 1.0.4 and earlier as well (cPanel does not use Horde Groupware
at this time).

cPanel customers should update their cPanel and WHM servers immediately to
prevent any chance of compromise. The patch will be available in builds
11.18.2 and greater (or 11.19.2 and greater for EDGE systems). The updated
builds will be available immediately to all fast update servers. The
builds will be available to all other update servers within one hour of
this posting.


To check which version of cPanel and WHM is on your server, simply log
into WebHost Manager (WHM) and look in the top right corner, or execute
the following command from the command line as root:

/usr/local/cpanel/cpanel -V

You can upgrade your server by navigating to 'cPanel' -> 'Upgrade to
Latest Version' in WebHost Manager or by executing the following from the
command line as root:

/scripts/upcp


It is recommended that all use of Horde 3.1.6 and earlier be stopped (on
cPanel and non-cPanel systems alike) until Horde updates can be applied.
You can disable Horde on your cPanel system by unchecking the box next to
'Server Configuration' -> 'Tweak Settings' -> 'Mail' -> 'Horde Webmail'
within WHM, and saving the page with the new settings.

News and Announcements

Emergency VPS server maintenance
July 21, 2009, 8:16 pm
To our valued customers,

We have...
Read More

NOTICE: Network Issue
July 20, 2008, 8:43 am
To our valued customers,

We are...
Read More

Scheduled Network Maintenance
April 4, 2008, 7:27 pm
On the morning of Friday April 11th, we will have...
Read More

Scheduled Maintenance - March 19, 2008 - 1AM to 4AM Central
March 7, 2008, 5:25 pm
We will be performing network maintenance on...
Read More


Subscribe to our list
Email Address: