Vulnerabilities > Cpanel

DATE CVE VULNERABILITY TITLE RISK
2019-08-02 CVE-2017-18439 Improper Input Validation vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).
network
low complexity
cpanel CWE-20
6.3
2019-08-02 CVE-2017-18438 XXE vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).
network
low complexity
cpanel CWE-611
6.3
2019-08-02 CVE-2017-18437 Injection vulnerability in Cpanel
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
local
low complexity
cpanel CWE-74
4.4
2019-08-02 CVE-2017-18436 Information Exposure vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
low complexity
cpanel CWE-200
3.5
2019-08-02 CVE-2017-18435 Unrestricted Upload of File with Dangerous Type vulnerability in Cpanel
cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
network
low complexity
cpanel CWE-434
7.3
2019-08-02 CVE-2017-18434 Improper Input Validation vulnerability in Cpanel
cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).
local
low complexity
cpanel CWE-20
7.8
2019-08-02 CVE-2017-18433 Improper Input Validation vulnerability in Cpanel
cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
network
low complexity
cpanel CWE-20
8.8
2019-08-02 CVE-2017-18432 Information Exposure vulnerability in Cpanel
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
local
low complexity
cpanel CWE-200
7.8
2019-08-02 CVE-2017-18431 Improper Input Validation vulnerability in Cpanel
cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
network
low complexity
cpanel CWE-20
7.5
2019-08-02 CVE-2017-18430 Improper Input Validation vulnerability in Cpanel
In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).
network
low complexity
cpanel CWE-20
4.7