Cpanel
by CPanel
CVEs (424)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-18474 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201). | ||
| CVE-2016-10775 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173). | ||
| CVE-2016-10770 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164). | ||
| CVE-2016-10768 | Med | 0.42 | 6.5 | 0.01 | Aug 5, 2019 | cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161). | ||
| CVE-2017-18410 | Med | 0.42 | 6.5 | 0.01 | Aug 2, 2019 | In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284). | ||
| CVE-2017-18409 | Med | 0.42 | 6.5 | 0.01 | Aug 2, 2019 | In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283). | ||
| CVE-2016-10821 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75). | ||
| CVE-2016-10819 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125). | ||
| CVE-2016-10818 | Med | 0.42 | 6.5 | 0.02 | Aug 1, 2019 | cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124). | ||
| CVE-2016-10815 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120). | ||
| CVE-2018-20952 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388). | ||
| CVE-2016-10832 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102). | ||
| CVE-2016-10829 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99). | ||
| CVE-2018-20934 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411). | ||
| CVE-2018-20930 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401). | ||
| CVE-2016-10849 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82). | ||
| CVE-2016-10844 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77). | ||
| CVE-2016-10842 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74). | ||
| CVE-2016-10838 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). | ||
| CVE-2016-10836 | Med | 0.42 | 6.5 | 0.01 | Aug 1, 2019 | cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). |
- risk 0.42cvss 6.5epss 0.01
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows arbitrary file-chown operations via reassign_post_terminate_cruft (SEC-173).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows arbitrary file-overwrite operations during a Roundcube update (SEC-164).
- risk 0.42cvss 6.5epss 0.01
cPanel before 60.0.25 allows file-overwrite operations during preparation for MySQL upgrades (SEC-161).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75).
- risk 0.42cvss 6.5epss 0.01
In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125).
- risk 0.42cvss 6.5epss 0.02
cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124).
- risk 0.42cvss 6.5epss 0.01
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
- risk 0.42cvss 6.5epss 0.01
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
- risk 0.42cvss 6.5epss 0.01
cPanel before 55.9999.141 allows FTP cPHulk bypass via account name munging (SEC-102).
- risk 0.42cvss 6.5epss 0.01
cPanel before 55.9999.141 allows arbitrary file-read operations because of a multipart form processing error (SEC-99).
- risk 0.42cvss 6.5epss 0.01
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).
- risk 0.42cvss 6.5epss 0.01
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).
- risk 0.42cvss 6.5epss 0.01
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).
- risk 0.42cvss 6.5epss 0.01
cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).
- risk 0.42cvss 6.5epss 0.01
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
Page 8 of 22