Search Results (Refine Search)
- Results Type: Overview
- Keyword (text search): cpe:2.3:a:cpanel:cpanel:11.52.1.3:*:*:*:*:*:*:*
- CPE Name Search: true
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2016-10843 |
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76). Published: August 01, 2019; 12:15:12 PM -0400 |
V4.0:(not available) V3.0: 8.1 HIGH V2.0: 5.5 MEDIUM |
CVE-2016-10842 |
cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74). Published: August 01, 2019; 12:15:12 PM -0400 |
V4.0:(not available) V3.0: 6.5 MEDIUM V2.0: 4.0 MEDIUM |
CVE-2016-10841 |
The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73). Published: August 01, 2019; 12:15:12 PM -0400 |
V4.0:(not available) V3.0: 5.3 MEDIUM V2.0: 2.1 LOW |
CVE-2016-10840 |
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72). Published: August 01, 2019; 12:15:12 PM -0400 |
V4.0:(not available) V3.0: 8.8 HIGH V2.0: 9.0 HIGH |
CVE-2016-10839 |
cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71). Published: August 01, 2019; 12:15:12 PM -0400 |
V4.0:(not available) V3.0: 8.1 HIGH V2.0: 5.5 MEDIUM |
CVE-2016-10838 |
cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70). Published: August 01, 2019; 12:15:12 PM -0400 |
V4.0:(not available) V3.0: 6.5 MEDIUM V2.0: 6.8 MEDIUM |
CVE-2016-10837 |
cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46). Published: August 01, 2019; 12:15:12 PM -0400 |
V4.0:(not available) V3.0: 7.5 HIGH V2.0: 8.5 HIGH |
CVE-2016-10836 |
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108). Published: August 01, 2019; 12:15:12 PM -0400 |
V4.0:(not available) V3.0: 6.5 MEDIUM V2.0: 4.0 MEDIUM |
CVE-2018-20923 |
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20922 |
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20921 |
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20920 |
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20919 |
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20918 |
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 6.1 MEDIUM V2.0: 4.3 MEDIUM |
CVE-2018-20917 |
cPanel before 70.0.23 allows any user to disable Solr (SEC-371). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 5.5 MEDIUM V2.0: 2.1 LOW |
CVE-2018-20916 |
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2018-20915 |
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). Published: August 01, 2019; 11:15:14 AM -0400 |
V4.0:(not available) V3.0: 5.4 MEDIUM V2.0: 3.5 LOW |
CVE-2018-20914 |
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 7.3 HIGH V2.0: 4.9 MEDIUM |
CVE-2018-20913 |
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 4.9 MEDIUM V2.0: 3.5 LOW |
CVE-2018-20912 |
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362). Published: August 01, 2019; 11:15:13 AM -0400 |
V4.0:(not available) V3.0: 6.3 MEDIUM V2.0: 6.5 MEDIUM |