Type: Privilege Escalation #1
Vulnerable Version: v1.43
Fixed Version: v1.431
DirectAdmin is a graphical web-based web hosting control panel designed to make administration of websites easier.
There is a flaw within the backup system that allows an attacker to use a carefully crafted symlink to overwrite any file on the server with their own content.
Proof of Concept:
Due to the nature of this security flaw, we will not be posting a Proof of Concept until a much later date.
We have deemed this vulnerability to be rated as CRITICAL due to the fact that a normal user can gain an instant root shell.
This vulnerability was tested against DirectAdmin v1.43.
This vulnerability was patched in DirectAdmin v1.431.
Vendor Contact Timeline:
2013-06-16: Vendor contacted via email.
2013-06-17: Vendor confirms vulnerability.
2013-06-17: Vendor issues v1.431 #2 update.
2013-06-19: Rack911 issues security advisory.