VYPR

Cpanel

by CPanel

CVEs (424)

  • CVE-2017-18445MedAug 2, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).

  • CVE-2017-18440MedAug 2, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).

  • CVE-2018-20937MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).

  • CVE-2016-10835MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 55.9999.141 allows a POP/IMAP cPHulk bypass via account name munging (SEC-107).

  • CVE-2018-20907MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432).

  • CVE-2018-20906MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430).

  • CVE-2018-20904MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427).

  • CVE-2018-20898MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396).

  • CVE-2018-20892MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 74.0.0 allows arbitrary zone file modifications because of incorrect CAA record handling (SEC-439).

  • CVE-2018-20890MedAug 1, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 74.0.0 allows arbitrary zone file modifications during record edits (SEC-426).

  • CVE-2019-14413MedJul 30, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).

  • CVE-2019-14408MedJul 30, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).

  • CVE-2019-14403MedJul 30, 2019
    risk 0.28cvss 4.3epss 0.01

    cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).

  • CVE-2020-29135MedNov 27, 2020
    risk 0.27cvss 4.1epss 0.01

    cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).

  • CVE-2017-18398LowAug 2, 2019
    risk 0.25cvss 3.8epss 0.01

    DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).

  • CVE-2017-18384LowAug 2, 2019
    risk 0.25cvss 3.8epss 0.00

    cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).

  • CVE-2018-20927LowAug 1, 2019
    risk 0.25cvss 3.8epss 0.00

    cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).

  • CVE-2018-20896LowAug 1, 2019
    risk 0.25cvss 3.9epss 0.00

    cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).

  • CVE-2017-18399LowAug 2, 2019
    risk 0.24cvss 3.7epss 0.01

    cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).

  • CVE-2017-18436LowAug 2, 2019
    risk 0.23cvss 3.5epss 0.00

    cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).

Page 17 of 22