VYPR

Cpanel

by CPanel

CVEs (427)

  • CVE-2016-10842MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).

  • CVE-2016-10838MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).

  • CVE-2016-10836MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).

  • CVE-2016-10857MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).

  • CVE-2016-10856MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).

  • CVE-2016-10852MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).

  • CVE-2018-20883MedAug 1, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).

  • CVE-2018-20864MedJul 30, 2019
    risk 0.42cvss 6.5epss 0.01

    cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).

  • CVE-2017-18469MedAug 5, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).

  • CVE-2017-18468MedAug 5, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).

  • CVE-2017-18447MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).

  • CVE-2017-18446MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).

  • CVE-2017-18439MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).

  • CVE-2017-18438MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).

  • CVE-2017-18403MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).

  • CVE-2017-18389MedAug 2, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).

  • CVE-2018-20931MedAug 1, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).

  • CVE-2018-20912MedAug 1, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).

  • CVE-2018-20879MedAug 1, 2019
    risk 0.41cvss 6.3epss 0.01

    cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).

  • CVE-2023-29489MedApr 27, 2023
    risk 0.40cvss 5.3epss 0.66

    An issue was discovered in cPanel before 11.109.9999.116. XSS can occur on the cpsrvd error page via an invalid webcall ID, aka SEC-669. The fixed versions are 11.109.9999.116, 11.108.0.13, 11.106.0.18, and 11.102.0.31.

Page 9 of 22