How could a user level script vulnerability allow root access unless the server itself was behind in security updates?
Edit:
Err not to take away from the value and importance of your security vulnerability notice.
I just don't see how Epoch's script alone, running at a normal user level would allow privledge escalation (to root) on a well secured/updated server.