VYPR

Cpanel

by CPanel

CVEs (424)

  • CVE-2016-10771HigAug 5, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 60.0.25 allows file-create and file-chmod operations during ModSecurity Audit logfile processing (SEC-165).

  • CVE-2016-10830HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 55.9999.141 allows ACL bypass for AppConfig applications via magic_revision (SEC-100).

  • CVE-2016-10825HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 55.9999.141 allows attackers to bypass a Security Policy by faking static documents (SEC-92).

  • CVE-2016-10847HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).

  • CVE-2016-10846HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).

  • CVE-2016-10845HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).

  • CVE-2016-10843HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).

  • CVE-2016-10839HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).

  • CVE-2016-10860HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 11.54.0.0 allows unauthorized zone modification via the WHM API (SEC-66).

  • CVE-2016-10859HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    cPanel before 11.54.0.0 allows unauthorized password changes via Webmail API commands (SEC-65).

  • CVE-2016-10800HigAug 7, 2019
    risk 0.51cvss 7.8epss 0.01

    cPanel before 58.0.4 allows demo-mode escape via Site Templates and Boxtrapper API calls (SEC-138).

  • CVE-2017-18463HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).

  • CVE-2017-18460HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).

  • CVE-2017-18459HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).

  • CVE-2017-18434HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).

  • CVE-2017-18432HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).

  • CVE-2017-18415HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).

  • CVE-2017-18413HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).

  • CVE-2017-18400HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.01

    cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).

  • CVE-2017-18390HigAug 2, 2019
    risk 0.51cvss 7.8epss 0.00

    cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).

Page 4 of 22