Server Software and Configuration Services
New csf v6.22
Changes:
- Security Fix – Sanitised user data input to prevent running unauthorised commands via the UI. A user would require root access to exploit this, so vulnerability is probably low. Thanks to Steven at Rack911.com for reporting this issue
- Added Password ENV variable check to Server Check on cPanel servers
- Update cPanel ACL Driver installations to change force cache update using “touch” instead of removing the cache
- Modified TOR URL in /etc/csf/csf.blocklists to use:
http://check.torproject.org/cgi-bin/TorBulkExitList.py?ip=1.1.1.1