Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2016-10771 | Hig | 0.53 | 8.1 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165). | ||
| CVE-2016-10830 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100). | ||
| CVE-2016-10825 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92). | ||
| CVE-2016-10847 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80). | ||
| CVE-2016-10846 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79). | ||
| CVE-2016-10845 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78). | ||
| CVE-2016-10843 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76). | ||
| CVE-2016-10839 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71). | ||
| CVE-2016-10860 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66). | ||
| CVE-2016-10859 | Hig | 0.53 | 8.1 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65). | ||
| CVE-2016-10800 | Hig | 0.51 | 7.8 | 0.01 | Aug 7, 2019 | cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138). | ||
| CVE-2017-18463 | Hig | 0.51 | 7.8 | 0.00 | Aug 2, 2019 | cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225). | ||
| CVE-2017-18460 | Hig | 0.51 | 7.8 | 0.00 | Aug 2, 2019 | cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221). | ||
| CVE-2017-18459 | Hig | 0.51 | 7.8 | 0.00 | Aug 2, 2019 | cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220). | ||
| CVE-2017-18434 | Hig | 0.51 | 7.8 | 0.00 | Aug 2, 2019 | cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237). | ||
| CVE-2017-18432 | Hig | 0.51 | 7.8 | 0.00 | Aug 2, 2019 | In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234). | ||
| CVE-2017-18415 | Hig | 0.51 | 7.8 | 0.00 | Aug 2, 2019 | cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302). | ||
| CVE-2017-18413 | Hig | 0.51 | 7.8 | 0.00 | Aug 2, 2019 | In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299). | ||
| CVE-2017-18400 | Hig | 0.51 | 7.8 | 0.01 | Aug 2, 2019 | cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333). | ||
| CVE-2017-18390 | Hig | 0.51 | 7.8 | 0.00 | Aug 2, 2019 | cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322). |
- risk 0.53cvss 8.1epss 0.01
cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).
- risk 0.53cvss 8.1epss 0.01
cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).
- risk 0.53cvss 8.1epss 0.01
cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).
- risk 0.53cvss 8.1epss 0.01
cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
- risk 0.53cvss 8.1epss 0.01
cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).
- risk 0.53cvss 8.1epss 0.01
cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
- risk 0.53cvss 8.1epss 0.01
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
- risk 0.53cvss 8.1epss 0.01
cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).
- risk 0.53cvss 8.1epss 0.01
cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).
- risk 0.53cvss 8.1epss 0.01
cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).
- risk 0.51cvss 7.8epss 0.01
cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).
- risk 0.51cvss 7.8epss 0.00
cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).
- risk 0.51cvss 7.8epss 0.00
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
- risk 0.51cvss 7.8epss 0.00
cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
- risk 0.51cvss 7.8epss 0.00
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).
- risk 0.51cvss 7.8epss 0.00
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
- risk 0.51cvss 7.8epss 0.00
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
- risk 0.51cvss 7.8epss 0.00
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
- risk 0.51cvss 7.8epss 0.01
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
- risk 0.51cvss 7.8epss 0.00
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).
Page 4 of 22