Vulnerabilities > Cpanel > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-08-02 | CVE-2017-18407 | Improper Verification of Cryptographic Signature vulnerability in Cpanel cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279). | 4.8 |
2019-08-02 | CVE-2017-18405 | Improper Input Validation vulnerability in Cpanel cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345). | 5.5 |
2019-08-02 | CVE-2017-18403 | Improper Access Control vulnerability in Cpanel cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337). | 6.3 |
2019-08-02 | CVE-2017-18402 | Cross-site Scripting vulnerability in Cpanel cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336). | 5.4 |
2019-08-02 | CVE-2017-18396 | Information Exposure vulnerability in Cpanel cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329). | 5.5 |
2019-08-02 | CVE-2017-18389 | Injection vulnerability in Cpanel cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318). | 6.3 |
2019-08-02 | CVE-2017-18385 | Improper Access Control vulnerability in Cpanel cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311). | 5.5 |
2019-08-01 | CVE-2016-10821 | Credentials Management vulnerability in Cpanel In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75). | 6.5 |
2019-08-01 | CVE-2016-10819 | Information Exposure Through Log Files vulnerability in Cpanel In cPanel before 57.9999.54, user log files become world-readable when rotated by cpanellogd (SEC-125). | 6.5 |
2019-08-01 | CVE-2016-10818 | Permission Issues vulnerability in Cpanel cPanel before 57.9999.54 incorrectly sets log-file permissions in dnsadmin-startup and spamd-startup (SEC-124). | 6.5 |