VYPR

Cpanel

by CPanel

CVEs (424)

  • CVE-2019-14412LowJul 30, 2019
    risk 0.21cvss 3.3epss 0.00

    Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).

  • CVE-2019-14410LowJul 30, 2019
    risk 0.21cvss 3.3epss 0.00

    Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).

  • CVE-2019-14402LowJul 30, 2019
    risk 0.21cvss 3.3epss 0.00

    cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).

  • CVE-2019-14396LowJul 30, 2019
    risk 0.21cvss 3.3epss 0.00

    API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).

  • CVE-2019-14395LowJul 30, 2019
    risk 0.21cvss 3.3epss 0.00

    cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).

  • CVE-2019-14391LowJul 30, 2019
    risk 0.21cvss 3.3epss 0.00

    cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).

  • CVE-2017-18404LowAug 2, 2019
    risk 0.20cvss 3.1epss 0.00

    cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).

  • CVE-2017-18466LowAug 5, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228).

  • CVE-2017-18455LowAug 2, 2019
    risk 0.18cvss 2.7epss 0.01

    In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).

  • CVE-2017-18426LowAug 2, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).

  • CVE-2017-18401LowAug 2, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).

  • CVE-2017-18395LowAug 2, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 68.0.15 does not block a username of ssl (SEC-328).

  • CVE-2017-18394LowAug 2, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).

  • CVE-2017-18393LowAug 2, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).

  • CVE-2017-18382LowAug 2, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).

  • CVE-2018-20938LowAug 1, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324).

  • CVE-2018-20932LowAug 1, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).

  • CVE-2018-20897LowAug 1, 2019
    risk 0.18cvss 2.8epss 0.00

    cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395).

  • CVE-2019-14407LowJul 30, 2019
    risk 0.18cvss 2.7epss 0.01

    cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).

  • CVE-2017-18428LowAug 2, 2019
    risk 0.16cvss 2.5epss 0.00

    In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).

Page 19 of 22