CVE-2004-1770

CRITICAL ⚠ Exploit

The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.

Affects 1 product across 1 vendor.

BCS8.88
CVSS 2.010.0
EPSS10.2%
Percentile95th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
◆ SAGE Intelligence — CITED Relevance Research Team

A critical vulnerability in cPanel 9.1.0 and potentially other versions allows remote attackers to execute arbitrary code through shell metacharacters in the user parameter on the login page.

BSID: BS-2004-GLOBAL-156403-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2004-1770?
A critical vulnerability in cPanel 9.1.0 and potentially other versions allows remote attackers to execute arbitrary code through shell metacharacters in the user parameter on the login page.
What is the CVSS score for CVE-2004-1770?
CVE-2004-1770 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 10.2%.
Is CVE-2004-1770 actively exploited?
Public exploit available for CVE-2004-1770. Exploitation risk elevated.
How do I remediate CVE-2004-1770?
Priority: IMMEDIATE. Advisory: http://www.kb.cert.org/vuls/id/831534 PSIRT: [email protected]
What systems are affected by CVE-2004-1770?
CVE-2004-1770 affects: Cpanel.
Vulnerability Details
CVE IDCVE-2004-1770
BSIDBS-2004-GLOBAL-156403-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2004-03-11
Last Modified2026-04-16
ICS Relevance0%
SourceNVD
Official Description

The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by injecting shell metacharacters into the user parameter on the login page, which can lead to arbitrary code execution with the privileges of the web server.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Cpanel Cpanel
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 8179 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Cpanel
CVE-2025-12539 10.0 The TNC Toolbox: Web Performance plugin for WordPress is vulnerable to Sensit... CVE-2003-1425 10.0 guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary comm... CVE-2004-1769 10.0 The "Allow cPanel users to reset their password via email" feature in cPanel ... CVE-2024-8767 9.9 Sensitive data disclosure and manipulation due to unnecessary privileges assi... CVE-2016-10817 9.8 cPanel before 57.9999.54 allows SQL Injection via the ModSecurity TailWatch l...
View all Cpanel CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →