Vulnerabilities > Ehcp

DATE CVE VULNERABILITY TITLE RISK
2018-05-11 CVE-2018-6619 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Ehcp Easy Hosting Control Panel 0.37.12.B
Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt.
local
low complexity
ehcp CWE-327
7.8
2018-05-11 CVE-2018-6618 Insufficiently Protected Credentials vulnerability in Ehcp Easy Hosting Control Panel 0.37.12.B
Easy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
local
low complexity
ehcp CWE-522
7.8
2018-05-11 CVE-2018-6617 Improper Authentication vulnerability in Ehcp Easy Hosting Control Panel 0.37.12.B
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password.
local
low complexity
ehcp CWE-287
7.8
2018-05-11 CVE-2018-6458 Cross-Site Request Forgery (CSRF) vulnerability in Ehcp Easy Hosting Control Panel 0.37.12.B
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
network
low complexity
ehcp CWE-352
8.8
2018-05-11 CVE-2018-6362 Cross-site Scripting vulnerability in Ehcp Easy Hosting Control Panel 0.37.12.B
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.
network
low complexity
ehcp CWE-79
6.1
2018-05-11 CVE-2018-6361 Cross-site Scripting vulnerability in Ehcp Easy Hosting Control Panel 0.37.12.B
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.
network
low complexity
ehcp CWE-79
6.1