Vulnerabilities > Cpanel > Low

DATE CVE VULNERABILITY TITLE RISK
2019-08-01 CVE-2018-20944 Information Exposure vulnerability in Cpanel
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
local
low complexity
cpanel CWE-200
2.1
2019-08-01 CVE-2018-20946 Information Exposure vulnerability in Cpanel
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
local
low complexity
cpanel CWE-200
2.1
2019-08-01 CVE-2018-20947 Exposure of Resource to Wrong Sphere vulnerability in Cpanel
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
local
low complexity
cpanel CWE-668
2.1
2019-08-01 CVE-2016-10841 Information Management Errors vulnerability in Cpanel
The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).
network
high complexity
cpanel CWE-199
2.1
2019-08-01 CVE-2018-20927 Improper Authorization vulnerability in Cpanel
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).
local
low complexity
cpanel CWE-285
2.1
2019-08-01 CVE-2018-20933 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
network
cpanel CWE-79
3.5
2019-08-01 CVE-2018-20935 Cross-site Scripting vulnerability in Cpanel
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).
network
cpanel CWE-79
3.5
2019-08-01 CVE-2016-10851 Cross-site Scripting vulnerability in Cpanel
cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
network
cpanel CWE-79
3.5
2019-08-01 CVE-2016-10853 Cross-site Scripting vulnerability in Cpanel
cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
network
cpanel CWE-79
3.5
2019-08-01 CVE-2016-10854 Cross-site Scripting vulnerability in Cpanel
cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
network
cpanel CWE-79
3.5