Vulnerabilities > Information Exposure

DATE CVE VULNERABILITY TITLE RISK
2019-08-02 CVE-2017-18424 Information Exposure vulnerability in Cpanel
In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
local
low complexity
cpanel CWE-200
3.3
2019-08-02 CVE-2017-18396 Information Exposure vulnerability in Cpanel
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).
local
low complexity
cpanel CWE-200
5.5
2019-08-02 CVE-2017-18391 Information Exposure vulnerability in Cpanel
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323).
local
high complexity
cpanel CWE-200
2.5
2019-08-01 CVE-2016-10815 Information Exposure vulnerability in Cpanel
cPanel before 57.9999.54 allows arbitrary file-read operations for Webmail accounts via Branding APIs (SEC-120).
network
low complexity
cpanel CWE-200
6.5
2019-08-01 CVE-2018-20952 Information Exposure vulnerability in Cpanel
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
network
low complexity
cpanel CWE-200
6.5
2019-08-01 CVE-2018-20946 Information Exposure vulnerability in Cpanel
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
local
low complexity
cpanel CWE-200
3.3
2019-08-01 CVE-2018-20944 Information Exposure vulnerability in Cpanel
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
local
low complexity
cpanel CWE-200
3.3
2019-08-01 CVE-2018-20943 Information Exposure vulnerability in Cpanel
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).
local
high complexity
cpanel CWE-200
2.5
2019-08-01 CVE-2018-20942 Information Exposure vulnerability in Cpanel
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).
local
high complexity
cpanel CWE-200
2.5
2019-08-01 CVE-2018-20941 Information Exposure vulnerability in Cpanel
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
local
high complexity
cpanel CWE-200
5.6