Vulnerabilities > Cpanel > High

DATE CVE VULNERABILITY TITLE RISK
2019-08-02 CVE-2017-18432 Information Exposure vulnerability in Cpanel
In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
local
low complexity
cpanel CWE-200
7.8
2019-08-02 CVE-2017-18431 Improper Input Validation vulnerability in Cpanel
cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
network
low complexity
cpanel CWE-20
7.5
2019-08-02 CVE-2017-18415 Improper Input Validation vulnerability in Cpanel
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
local
low complexity
cpanel CWE-20
7.8
2019-08-02 CVE-2017-18414 Open Redirect vulnerability in Cpanel
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
network
low complexity
cpanel CWE-601
7.4
2019-08-02 CVE-2017-18413 Permissions, Privileges, and Access Controls vulnerability in Cpanel
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
local
low complexity
cpanel CWE-264
7.8
2019-08-02 CVE-2017-18406 SQL Injection vulnerability in Cpanel
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
network
low complexity
cpanel CWE-89
7.5
2019-08-02 CVE-2017-18400 Command Injection vulnerability in Cpanel
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
local
low complexity
cpanel CWE-77
7.8
2019-08-02 CVE-2017-18390 Permission Issues vulnerability in Cpanel
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).
local
low complexity
cpanel CWE-275
7.8
2019-08-02 CVE-2017-18388 Improper Input Validation vulnerability in Cpanel
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
local
low complexity
cpanel CWE-20
7.8
2019-08-02 CVE-2017-18387 Injection vulnerability in Cpanel
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
network
low complexity
cpanel CWE-74
7.2