Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:cpanel:cpanel:11.52.1.3:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2016-10805 |
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-109). Published: August 07, 2019; 9:15:12 AM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 6.5 MEDIUM |
CVE-2016-10804 |
The SQLite journal feature in cPanel before 57.9999.54 allows arbitrary file-overwrite operations during Horde Restore (SEC-58). Published: August 07, 2019; 9:15:12 AM -0400 |
V4.0:(not available) V3.0: 8.1 HIGH V2.0: 8.7 HIGH |
CVE-2016-10802 |
cPanel before 58.0.4 allows code execution in the context of other user accounts through the PHP CGI handler (SEC-142). Published: August 07, 2019; 9:15:12 AM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 6.5 MEDIUM |
CVE-2016-10799 |
cPanel before 58.0.4 does not set the Pear tmp directory during a PHP installation (SEC-137). Published: August 07, 2019; 9:15:12 AM -0400 |
V4.0:(not available) V3.0: 5.5 MEDIUM V2.0: 2.1 LOW |
CVE-2016-10796 |
cPanel before 58.0.4 initially uses weak permissions for Apache HTTP Server log files (SEC-130). Published: August 06, 2019; 10:15:11 AM -0400 |
V4.0:(not available) V3.0: 3.3 LOW V2.0: 2.1 LOW |
CVE-2016-10795 |
cPanel before 59.9999.145 allows stored XSS in the WHM tail_upcp2.cgi interface (SEC-156). Published: August 06, 2019; 10:15:11 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2016-10794 |
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154). Published: August 06, 2019; 10:15:11 AM -0400 |
V4.0:(not available) V3.0: 6.5 MEDIUM V2.0: 4.0 MEDIUM |
CVE-2016-10793 |
cPanel before 59.9999.145 allows arbitrary code execution due to an incorrect #! in Mail::SPF scripts (SEC-152). Published: August 06, 2019; 10:15:11 AM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 6.5 MEDIUM |
CVE-2016-10792 |
cPanel before 59.9999.145 allows code execution in the context of other accounts via mailman list archives (SEC-141). Published: August 06, 2019; 10:15:11 AM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 6.5 MEDIUM |
CVE-2017-18426 |
cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288). Published: August 02, 2019; 12:15:12 PM -0400 |
V4.0:(not available) V3.0: 2.7 LOW V2.0: 4.0 MEDIUM |
CVE-2017-18420 |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269). Published: August 02, 2019; 12:15:11 PM -0400 |
V4.0:(not available) V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2017-18419 |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266). Published: August 02, 2019; 12:15:11 PM -0400 |
V4.0:(not available) V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2017-18418 |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265). Published: August 02, 2019; 12:15:11 PM -0400 |
V4.0:(not available) V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2017-18417 |
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263). Published: August 02, 2019; 12:15:11 PM -0400 |
V4.0:(not available) V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2017-18416 |
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303). Published: August 02, 2019; 10:15:13 AM -0400 |
V4.0:(not available) V3.0: 5.5 MEDIUM V2.0: 3.6 LOW |
CVE-2017-18415 |
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302). Published: August 02, 2019; 10:15:13 AM -0400 |
V4.0:(not available) V3.0: 7.8 HIGH V2.0: 4.6 MEDIUM |
CVE-2017-18414 |
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300). Published: August 02, 2019; 10:15:13 AM -0400 |
V4.0:(not available) V3.0: 7.4 HIGH V2.0: 5.8 MEDIUM |
CVE-2016-10826 |
cPanel before 55.9999.141 allows attackers to bypass Two Factor Authentication via DNS clustering requests (SEC-93). Published: August 01, 2019; 3:15:14 PM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 6.5 MEDIUM |
CVE-2016-10821 |
In cPanel before 55.9999.141, Scripts/addpop reveals a command-line password in a process list (SEC-75). Published: August 01, 2019; 3:15:14 PM -0400 |
V4.0:(not available) V3.0: 6.5 MEDIUM V2.0: 4.0 MEDIUM |
CVE-2016-10820 |
cPanel before 55.9999.141 allows daemons to access their controlling TTYs (SEC-31). Published: August 01, 2019; 3:15:14 PM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 9.0 HIGH |