Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-20492 | Hig | 0.57 | 8.8 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516). | ||
| CVE-2019-20490 | Hig | 0.57 | 8.8 | 0.01 | Mar 17, 2020 | cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499). | ||
| CVE-2019-17375 | Hig | 0.57 | 8.8 | 0.01 | Oct 9, 2019 | cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517). | ||
| CVE-2016-10812 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117). | ||
| CVE-2016-10811 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116). | ||
| CVE-2016-10810 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115). | ||
| CVE-2016-10809 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114). | ||
| CVE-2016-10808 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113). | ||
| CVE-2016-10805 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109). | ||
| CVE-2016-10802 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142). | ||
| CVE-2016-10801 | Hig | 0.57 | 8.8 | 0.01 | Aug 7, 2019 | cPanel before 58.0.4 has improper session handling for shared users (SEC-139). | ||
| CVE-2016-10793 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152). | ||
| CVE-2016-10792 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141). | ||
| CVE-2016-10789 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2019 | cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191). | ||
| CVE-2016-10788 | Hig | 0.57 | 8.8 | 0.02 | Aug 6, 2019 | cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188). | ||
| CVE-2017-18475 | Hig | 0.57 | 8.8 | 0.01 | Aug 5, 2019 | In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204). | ||
| CVE-2017-18470 | Hig | 0.57 | 8.8 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196). | ||
| CVE-2016-10773 | Hig | 0.57 | 8.8 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171). | ||
| CVE-2017-18433 | Hig | 0.57 | 8.8 | 0.02 | Aug 2, 2019 | cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236). | ||
| CVE-2016-10826 | Hig | 0.57 | 8.8 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93). |
- risk 0.57cvss 8.8epss 0.01
cPanel before 82.0.18 allows authentication bypass because of misparsing of the format of the password file (SEC-516).
- risk 0.57cvss 8.8epss 0.01
cPanel before 82.0.18 allows authentication bypass because webmail usernames are processed inconsistently (SEC-499).
- risk 0.57cvss 8.8epss 0.01
cPanel before 82.0.15 allows API token credentials to persist after an account has been renamed or terminated (SEC-517).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/enablefileprotect exposed TTYs (SEC-117).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 57.9999.54, /scripts/addpop and /scripts/delpop exposed TTYs (SEC-113).
- risk 0.57cvss 8.8epss 0.01
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109).
- risk 0.57cvss 8.8epss 0.01
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142).
- risk 0.57cvss 8.8epss 0.01
cPanel before 58.0.4 has improper session handling for shared users (SEC-139).
- risk 0.57cvss 8.8epss 0.01
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152).
- risk 0.57cvss 8.8epss 0.01
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141).
- risk 0.57cvss 8.8epss 0.01
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
- risk 0.57cvss 8.8epss 0.02
cPanel before 60.0.25 allows arbitrary code execution via Maketext in PostgreSQL adminbin (SEC-188).
- risk 0.57cvss 8.8epss 0.01
In cPanel before 62.0.4, Exim piped filters ran in the context of an incorrect user account when delivering to a system user (SEC-204).
- risk 0.57cvss 8.8epss 0.01
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
- risk 0.57cvss 8.8epss 0.01
cPanel before 60.0.25 allows format-string injection in exception-message handling (SEC-171).
- risk 0.57cvss 8.8epss 0.02
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
- risk 0.57cvss 8.8epss 0.01
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93).
Page 2 of 22