Vulnerabilities > Cpanel > Cpanel > 64.0.18

DATE CVE VULNERABILITY TITLE RISK
2019-08-02 CVE-2017-18440 Improper Input Validation vulnerability in Cpanel
cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
network
low complexity
cpanel CWE-20
4.0
2019-08-02 CVE-2017-18439 Improper Input Validation vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).
network
low complexity
cpanel CWE-20
6.5
2019-08-02 CVE-2017-18438 XXE vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).
network
low complexity
cpanel CWE-611
6.5
2019-08-02 CVE-2017-18437 Injection vulnerability in Cpanel
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
local
low complexity
cpanel CWE-74
3.6
2019-08-02 CVE-2017-18436 Information Exposure vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
low complexity
cpanel CWE-200
2.7
2019-08-02 CVE-2017-18435 Unrestricted Upload of File with Dangerous Type vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
network
low complexity
cpanel CWE-434
7.5
2019-08-02 CVE-2017-18434 Improper Input Validation vulnerability in Cpanel
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).
local
low complexity
cpanel CWE-20
7.2
2019-08-02 CVE-2017-18433 Improper Input Validation vulnerability in Cpanel
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
network
low complexity
cpanel CWE-20
critical
9.0
2019-08-02 CVE-2017-18432 Information Exposure vulnerability in Cpanel
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
local
low complexity
cpanel CWE-200
2.1
2019-08-02 CVE-2017-18430 Improper Input Validation vulnerability in Cpanel
In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).
local
low complexity
cpanel CWE-20
4.6