cpanel

426 tracked vulnerabilities.

CVE-2017-18438 MEDIUM
cPanel 55.9999.61-64.0.20 - Authenticated Remote Code Execution via Encoding API
Aug 02, 2019
CVSS 6.3
EPSS 0.00
CVE-2017-18437 MEDIUM
cPanel < 56.0.49 - Authenticated Remote Code Execution via Webmail Forwarder
Aug 02, 2019
CVSS 4.4
EPSS 0.00
CVE-2017-18436 LOW
cPanel 55.9999.61-56.0.49 - Unauthenticated Sensitive File Read via Fileman::getfileactions API2 Call
Aug 02, 2019
CVSS 3.5
EPSS 0.00
CVE-2017-18435 HIGH
cPanel 55.9999.61-56.0.49 - Unauthenticated Remote Code Execution via BoxTrapper API
Aug 02, 2019
CVSS 7.3
EPSS 0.01
CVE-2017-18434 HIGH
cPanel 55.9999.61-64.0.20 - Remote Code Execution via SET_VHOST_LANG_PACKAGE Multilang Adminbin Call
Aug 02, 2019
CVSS 7.8
EPSS 0.00
CVE-2017-18433 HIGH
cPanel 55.9999.61-64.0.20 - Remote Code Execution via store_filter API
Aug 02, 2019
CVSS 8.8
EPSS 0.01
CVE-2017-18432 HIGH
cPanel 55.9999.61-56.0.49 - Database Password Exposure via Horde MySQL to SQLite Conversion
Aug 02, 2019
CVSS 7.8
EPSS 0.00
CVE-2017-18431 HIGH
cPanel 65.9999.38-65.9999.x - Improper Input Validation in Suspend/Unsuspend Operations
Aug 02, 2019
CVSS 7.5
EPSS 0.00
CVE-2017-18430 MEDIUM
cPanel 55.9999.61-66.0.2 - Improper Input Validation in reassign_post_terminate_cruft
Aug 02, 2019
CVSS 4.7
EPSS 0.00
CVE-2017-18429 LOW
cPanel 55.9999.61-66.0.2 - Information Disclosure via Apache SSL Domain Logs
Aug 02, 2019
CVSS 3.3
EPSS 0.00
CVE-2017-18428 LOW
cPanel 55.9999.61-56.0.51 - Unauthorized Sensitive Information Exposure via Apache HTTP Server Domlogs
Aug 02, 2019
CVSS 2.5
EPSS 0.00
CVE-2017-18427 LOW
cPanel 55.9999.61-66.0.2 - Weak Log-File Permissions After Account Modification
Aug 02, 2019
CVSS 3.3
EPSS 0.00
CVE-2017-18426 LOW
cPanel < 66.0.2 - Unauthorized Domain Log File Access
Aug 02, 2019
CVSS 2.7
EPSS 0.00
CVE-2017-18425 LOW
cPanel 56.0.1-56.0.51 - Unprotected Error Log File Creation
Aug 02, 2019
CVSS 2.5
EPSS 0.00
CVE-2017-18424 LOW
cPanel 60.0.3-60.0.45 - Unauthorized Exposure of Sensitive Information via Apache Configuration File
Aug 02, 2019
CVSS 3.3
EPSS 0.00
CVE-2017-18423 LOW
cPanel 56.0.1-56.0.51 - Sensitive Information Exposure via Domain Log File
Aug 02, 2019
CVSS 3.3
EPSS 0.00
CVE-2017-18422 LOW
cPanel 56.0.1-56.0.51 - Weak File Permissions in EasyApache 4 Conversion
Aug 02, 2019
CVSS 3.3
EPSS 0.00
CVE-2017-18421 LOW
cPanel 60.0.3-60.0.45 - Improper Access Control
Aug 02, 2019
CVSS 3.3
EPSS 0.00
CVE-2017-18420 MEDIUM
cPanel < 66.0.2 - Stored Cross-Site Scripting in WHM cPAddons Processing
Aug 02, 2019
CVSS 5.4
EPSS 0.00
CVE-2017-18419 MEDIUM
cPanel < 66.0.2 - Stored Cross-Site Scripting during WHM cPAddons Uninstallation
Aug 02, 2019
CVSS 5.4
EPSS 0.00
CVE-2017-18418 MEDIUM
cPanel < 66.0.2 - Stored Cross-Site Scripting in WHM cPAddons File Operations
Aug 02, 2019
CVSS 5.4
EPSS 0.00
CVE-2017-18417 MEDIUM
cPanel < 66.0.2 - Stored Cross-Site Scripting via WHM cPAddons Installation
Aug 02, 2019
CVSS 5.4
EPSS 0.00
CVE-2017-18416 MEDIUM
cPanel < 56.0.52 - Arbitrary File Overwrite during Roundcube SQLite Schema Update
Aug 02, 2019
CVSS 5.5
EPSS 0.00
CVE-2017-18415 HIGH
cPanel < 56.0.52 - Remote Code Execution via Mailman Environment Variable Injection
Aug 02, 2019
CVSS 7.8
EPSS 0.00
CVE-2017-18414 HIGH
cPanel < 56.0.52 - Open Redirect via /unprotected/redirect.html
Aug 02, 2019
CVSS 7.4
EPSS 0.00