Vulnerabilities > Cpanel > Cpanel > 63.9999.74

DATE CVE VULNERABILITY TITLE RISK
2019-08-02 CVE-2017-18437 Injection vulnerability in Cpanel
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
local
low complexity
cpanel CWE-74
3.6
2019-08-02 CVE-2017-18436 Information Exposure vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
low complexity
cpanel CWE-200
2.7
2019-08-02 CVE-2017-18435 Unrestricted Upload of File with Dangerous Type vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
network
low complexity
cpanel CWE-434
7.5
2019-08-02 CVE-2017-18434 Improper Input Validation vulnerability in Cpanel
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).
local
low complexity
cpanel CWE-20
7.2
2019-08-02 CVE-2017-18433 Improper Input Validation vulnerability in Cpanel
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
network
low complexity
cpanel CWE-20
critical
9.0
2019-08-02 CVE-2017-18432 Information Exposure vulnerability in Cpanel
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
local
low complexity
cpanel CWE-200
2.1
2019-08-02 CVE-2017-18430 Improper Input Validation vulnerability in Cpanel
In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).
local
low complexity
cpanel CWE-20
4.6
2019-08-02 CVE-2017-18429 7PK - Security Features vulnerability in Cpanel
In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
local
low complexity
cpanel CWE-254
2.1
2019-08-02 CVE-2017-18428 Information Exposure vulnerability in Cpanel
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
local
cpanel CWE-200
1.9
2019-08-02 CVE-2017-18427 Permission Issues vulnerability in Cpanel
In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
local
low complexity
cpanel CWE-275
2.1