VYPR

Cpanel

by CPanel

CVEs (424)

  • CVE-2017-18462HigAug 5, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).

  • CVE-2017-18431HigAug 2, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).

  • CVE-2017-18406HigAug 2, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).

  • CVE-2016-10833HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 55.9999.141 mishandles username-based blocking for PRE requests in cPHulkd (SEC-104).

  • CVE-2016-10837HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.02

    cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).

  • CVE-2015-9291HigAug 1, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).

  • CVE-2019-14388HigJul 30, 2019
    risk 0.49cvss 7.5epss 0.01

    cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).

  • CVE-2017-18435HigAug 2, 2019
    risk 0.48cvss 7.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).

  • CVE-2017-18414HigAug 2, 2019
    risk 0.48cvss 7.4epss 0.01

    cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).

  • CVE-2018-20914HigAug 1, 2019
    risk 0.48cvss 7.3epss 0.01

    In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).

  • CVE-2021-38585HigAug 11, 2021
    risk 0.47cvss 7.2epss 0.01

    The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).

  • CVE-2021-38584HigAug 11, 2021
    risk 0.47cvss 7.2epss 0.01

    The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).

  • CVE-2020-10120HigMar 17, 2020
    risk 0.47cvss 7.2epss 0.03

    cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).

  • CVE-2020-10115HigMar 17, 2020
    risk 0.47cvss 7.2epss 0.02

    cPanel before 84.0.20, when PowerDNS is used, allows arbitrary code execution as root via dnsadmin. (SEC-537).

  • CVE-2017-18387HigAug 2, 2019
    risk 0.47cvss 7.2epss 0.02

    cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).

  • CVE-2017-18386HigAug 2, 2019
    risk 0.47cvss 7.2epss 0.02

    cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).

  • CVE-2016-10831HigAug 1, 2019
    risk 0.47cvss 7.2epss 0.01

    cPanel before 55.9999.141 does not perform as two-factor authentication check when possessing another account (SEC-101).

  • CVE-2016-10848HigAug 1, 2019
    risk 0.47cvss 7.2epss 0.01

    cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).

  • CVE-2018-20911HigAug 1, 2019
    risk 0.47cvss 7.2epss 0.02

    cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).

  • CVE-2018-20895HigAug 1, 2019
    risk 0.47cvss 7.2epss 0.01

    In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393).

Page 6 of 22