VYPR

Cpanel

by CPanel

CVEs (413)

  • CVE-2018-20870Jul 30, 2019
    risk 0.00cvss epss 0.00

    The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).

  • CVE-2018-20869Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).

  • CVE-2018-20862Jul 30, 2019
    risk 0.00cvss epss 0.00

    cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).

  • CVE-2018-20868Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).

  • CVE-2018-20866Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).

  • CVE-2018-20865Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).

  • CVE-2018-20864Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).

  • CVE-2018-20863Jul 30, 2019
    risk 0.00cvss epss 0.02

    cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).

  • CVE-2019-14414Jul 30, 2019
    risk 0.00cvss epss 0.00

    In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).

  • CVE-2019-14413Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).

  • CVE-2019-14412Jul 30, 2019
    risk 0.00cvss epss 0.00

    Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).

  • CVE-2019-14411Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).

  • CVE-2019-14410Jul 30, 2019
    risk 0.00cvss epss 0.00

    Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).

  • CVE-2019-14409Jul 30, 2019
    risk 0.00cvss epss 0.00

    cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).

  • CVE-2019-14408Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).

  • CVE-2019-14407Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).

  • CVE-2019-14406Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).

  • CVE-2019-14405Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).

  • CVE-2019-14404Jul 30, 2019
    risk 0.00cvss epss 0.00

    cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).

  • CVE-2019-14403Jul 30, 2019
    risk 0.00cvss epss 0.01

    cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).