Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18425 | Low | 0.16 | 2.5 | 0.00 | Aug 2, 2019 | In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280). | ||
| CVE-2017-18412 | Low | 0.16 | 2.5 | 0.00 | Aug 2, 2019 | cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296). | ||
| CVE-2017-18391 | Low | 0.16 | 2.5 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323). | ||
| CVE-2018-20943 | Low | 0.16 | 2.5 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352). | ||
| CVE-2018-20942 | Low | 0.16 | 2.5 | 0.00 | Aug 1, 2019 | cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351). | ||
| CVE-2018-20893 | Low | 0.15 | 2.3 | 0.00 | Aug 1, 2019 | cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442). | ||
| CVE-2017-18392 | Low | 0.13 | 2.0 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325). | ||
| CVE-2004-1769 | 0.05 | — | 0.35 | Mar 11, 2004 | The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass. | |||
| CVE-2008-6843 | 0.04 | — | 0.07 | Jul 2, 2009 | Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot dot) in the sup3r parameter. | |||
| CVE-2004-1770 | 0.04 | — | 0.10 | Mar 11, 2004 | The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter. | |||
| CVE-2003-1425 | 0.04 | — | 0.11 | Dec 31, 2003 | guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter. | |||
| CVE-2009-4823 | 0.03 | — | 0.02 | Apr 27, 2010 | Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter. | |||
| CVE-2008-7142 | 0.03 | — | 0.03 | Sep 1, 2009 | Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers to list arbitrary directories via the showtree parameter. | |||
| CVE-2008-6927 | 0.03 | — | 0.04 | Aug 10, 2009 | Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote attackers to inject arbitrary web script or HTML via the (1) localapp, (2) updatedir, (3) scriptpath_show, (4) domain_show, (5)… | |||
| CVE-2009-2275 | 0.03 | — | 0.04 | Jul 1, 2009 | Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter. | |||
| CVE-2008-2478 | 0.03 | — | 0.04 | May 28, 2008 | scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this,… | |||
| CVE-2008-2070 | 0.03 | — | 0.02 | May 12, 2008 | The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase,… | |||
| CVE-2008-1499 | 0.03 | — | 0.01 | Mar 25, 2008 | Cross-site scripting (XSS) vulnerability in frontend/x/manpage.html in cPanel 11.18.3 and 11.21.0-BETA allows remote attackers to inject arbitrary web script or HTML via the query string. | |||
| CVE-2007-4022 | 0.03 | — | 0.02 | Jul 26, 2007 | Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter. | |||
| CVE-2006-6523 | 0.03 | — | 0.02 | Dec 14, 2006 | Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTML via the account parameter. |
- risk 0.16cvss 2.5epss 0.00
In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
- risk 0.16cvss 2.5epss 0.00
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
- risk 0.16cvss 2.5epss 0.00
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323).
- risk 0.16cvss 2.5epss 0.00
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).
- risk 0.16cvss 2.5epss 0.00
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).
- risk 0.15cvss 2.3epss 0.00
cPanel before 74.0.0 allows file-rename operations during account renames (SEC-442).
- risk 0.13cvss 2.0epss 0.01
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).
- CVE-2004-1769Mar 11, 2004risk 0.05cvss —epss 0.35
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to execute arbitrary code via the user parameter to resetpass.
- CVE-2008-6843Jul 2, 2009risk 0.04cvss —epss 0.07
Directory traversal vulnerability in index.php in Fantastico, as used with cPanel 11.x, allows remote attackers to read arbitrary files via a .. (dot dot) in the sup3r parameter.
- CVE-2004-1770Mar 11, 2004risk 0.04cvss —epss 0.10
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user parameter.
- CVE-2003-1425Dec 31, 2003risk 0.04cvss —epss 0.11
guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.
- CVE-2009-4823Apr 27, 2010risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.
- CVE-2008-7142Sep 1, 2009risk 0.03cvss —epss 0.03
Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers to list arbitrary directories via the showtree parameter.
- CVE-2008-6927Aug 10, 2009risk 0.03cvss —epss 0.04
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote attackers to inject arbitrary web script or HTML via the (1) localapp, (2) updatedir, (3) scriptpath_show, (4) domain_show, (5)…
- CVE-2009-2275Jul 1, 2009risk 0.03cvss —epss 0.04
Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter.
- CVE-2008-2478May 28, 2008risk 0.03cvss —epss 0.04
scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to execute arbitrary code via shell metacharacters in the Email address field (aka Email text box). NOTE: the vendor disputes this,…
- CVE-2008-2070May 12, 2008risk 0.03cvss —epss 0.02
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS protection and inject arbitrary script or HTML via repeated, improperly-ordered "<" and ">" characters in the (1) issue parameter to scripts2/knowlegebase,…
- CVE-2008-1499Mar 25, 2008risk 0.03cvss —epss 0.01
Cross-site scripting (XSS) vulnerability in frontend/x/manpage.html in cPanel 11.18.3 and 11.21.0-BETA allows remote attackers to inject arbitrary web script or HTML via the query string.
- CVE-2007-4022Jul 26, 2007risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.
- CVE-2006-6523Dec 14, 2006risk 0.03cvss —epss 0.02
Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTML via the account parameter.
Page 20 of 22