cPanel 65.9999.78

CPE Details

cPanel 65.9999.78
65.9999.78
2019-07-31
15h41 +00:00
2019-07-31
15h41 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:cpanel:cpanel:65.9999.78:*:*:*:*:*:*:*

Informations

Vendor

cpanel

Product

cpanel

Version

65.9999.78

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2021-38584 2021-08-11 20h56 +00:00 The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585).
7.2
High
CVE-2021-38585 2021-08-11 20h55 +00:00 The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585).
7.2
High
CVE-2021-38587 2021-08-11 20h55 +00:00 In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586).
7.5
High
CVE-2021-38588 2021-08-11 20h55 +00:00 In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587).
8.1
High
CVE-2021-31803 2021-04-26 05h30 +00:00 cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581).
6.1
Medium
CVE-2021-26266 2021-01-26 02h35 +00:00 cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578).
7.5
High
CVE-2021-26267 2021-01-26 02h35 +00:00 cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579).
7.5
High
CVE-2020-29137 2020-11-27 00h34 +00:00 cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577).
6.1
Medium
CVE-2020-29135 2020-11-27 00h34 +00:00 cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567).
4.1
Medium
CVE-2020-26098 2020-09-25 03h43 +00:00 cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485).
9.8
Critical
CVE-2020-26099 2020-09-25 03h43 +00:00 cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491).
7.5
High
CVE-2020-26100 2020-09-25 03h43 +00:00 chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497).
9.8
Critical
CVE-2020-26101 2020-09-25 03h43 +00:00 In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549).
9.8
Critical
CVE-2020-26102 2020-09-25 03h42 +00:00 In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550).
7.5
High
CVE-2020-26103 2020-09-25 03h42 +00:00 In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551).
7.5
High
CVE-2020-26104 2020-09-25 03h42 +00:00 In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552).
7.5
High
CVE-2020-26105 2020-09-25 03h42 +00:00 In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554).
9.8
Critical
CVE-2020-26106 2020-09-25 03h42 +00:00 cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558).
7.5
High
CVE-2020-26107 2020-09-25 03h42 +00:00 cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561).
7.5
High
CVE-2020-26108 2020-09-25 03h42 +00:00 cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488).
9.8
Critical
CVE-2020-26109 2020-09-25 03h41 +00:00 cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557).
7.5
High
CVE-2020-26110 2020-09-25 03h40 +00:00 cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564).
6.1
Medium
CVE-2020-26111 2020-09-25 03h40 +00:00 cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566).
6.1
Medium
CVE-2020-26112 2020-09-25 03h40 +00:00 The email quota cache in cPanel before 90.0.10 allows overwriting of files.
7.5
High
CVE-2020-26113 2020-09-25 03h40 +00:00 cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569).
6.1
Medium
CVE-2020-26114 2020-09-25 03h40 +00:00 cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573).
6.1
Medium
CVE-2020-26115 2020-09-25 03h40 +00:00 cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574).
6.1
Medium
CVE-2020-10120 2020-03-17 13h39 +00:00 cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545).
7.2
High
CVE-2020-10119 2020-03-17 13h38 +00:00 cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544).
9.8
Critical
CVE-2019-17380 2019-10-09 13h11 +00:00 cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528).
6.1
Medium
CVE-2017-18431 2019-08-02 13h56 +00:00 cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
7.5
High
CVE-2017-18430 2019-08-02 13h55 +00:00 In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).
4.7
Medium
CVE-2017-18429 2019-08-02 13h54 +00:00 In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
3.3
Low
CVE-2017-18428 2019-08-02 13h47 +00:00 In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
2.5
Low
CVE-2017-18427 2019-08-02 13h46 +00:00 In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
3.3
Low
CVE-2017-18426 2019-08-02 13h44 +00:00 cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
2.7
Low
CVE-2017-18420 2019-08-02 13h36 +00:00 cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
5.4
Medium
CVE-2017-18419 2019-08-02 13h35 +00:00 cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
5.4
Medium
CVE-2017-18418 2019-08-02 13h34 +00:00 cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
5.4
Medium
CVE-2017-18417 2019-08-02 13h33 +00:00 cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
5.4
Medium
CVE-2017-18416 2019-08-02 11h53 +00:00 cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
5.5
Medium
CVE-2017-18415 2019-08-02 11h53 +00:00 cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
7.8
High
CVE-2017-18414 2019-08-02 11h52 +00:00 cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
7.4
High
CVE-2017-18413 2019-08-02 11h51 +00:00 In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
7.8
High
CVE-2017-18412 2019-08-02 11h50 +00:00 cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
2.5
Low
CVE-2017-18411 2019-08-02 11h50 +00:00 The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
6.8
Medium
CVE-2017-18410 2019-08-02 11h49 +00:00 In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
6.5
Medium
CVE-2017-18409 2019-08-02 11h48 +00:00 In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
6.5
Medium
CVE-2017-18408 2019-08-02 11h47 +00:00 cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
5.4
Medium
CVE-2017-18407 2019-08-02 11h46 +00:00 cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
4.8
Medium
CVE-2017-18406 2019-08-02 11h45 +00:00 cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
7.5
High
CVE-2017-18405 2019-08-02 11h13 +00:00 cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).
5.5
Medium
CVE-2017-18404 2019-08-02 11h12 +00:00 cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).
3.1
Low
CVE-2017-18403 2019-08-02 11h12 +00:00 cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).
6.3
Medium
CVE-2017-18402 2019-08-02 11h11 +00:00 cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).
5.4
Medium
CVE-2017-18401 2019-08-02 11h10 +00:00 cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334).
2.7
Low
CVE-2017-18400 2019-08-02 11h09 +00:00 cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333).
7.8
High
CVE-2017-18399 2019-08-02 11h08 +00:00 cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332).
3.7
Low
CVE-2017-18398 2019-08-02 11h08 +00:00 DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331).
3.8
Low
CVE-2017-18397 2019-08-02 11h07 +00:00 cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330).
3.3
Low
CVE-2017-18396 2019-08-02 11h06 +00:00 cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329).
5.5
Medium
CVE-2017-18395 2019-08-02 11h05 +00:00 cPanel before 68.0.15 does not block a username of ssl (SEC-328).
2.7
Low
CVE-2017-18394 2019-08-02 11h04 +00:00 cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327).
2.7
Low
CVE-2017-18393 2019-08-02 11h04 +00:00 cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326).
2.7
Low
CVE-2017-18392 2019-08-02 11h03 +00:00 cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325).
2
Low
CVE-2017-18391 2019-08-02 10h33 +00:00 cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323).
2.5
Low
CVE-2017-18390 2019-08-02 10h33 +00:00 cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322).
7.8
High
CVE-2017-18389 2019-08-02 10h32 +00:00 cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318).
6.3
Medium
CVE-2017-18388 2019-08-02 10h31 +00:00 cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315).
7.8
High
CVE-2017-18387 2019-08-02 10h30 +00:00 cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314).
7.2
High
CVE-2017-18386 2019-08-02 10h29 +00:00 cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313).
7.2
High
CVE-2017-18385 2019-08-02 10h22 +00:00 cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311).
5.5
Medium
CVE-2017-18384 2019-08-02 10h21 +00:00 cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310).
3.8
Low
CVE-2017-18383 2019-08-02 10h20 +00:00 cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309).
7.8
High
CVE-2017-18382 2019-08-02 10h19 +00:00 cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306).
2.7
Low
CVE-2018-20953 2019-08-01 14h20 +00:00 cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389).
6.1
Medium
CVE-2018-20952 2019-08-01 14h19 +00:00 cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
6.5
Medium
CVE-2018-20951 2019-08-01 14h18 +00:00 cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387).
6.1
Medium
CVE-2018-20950 2019-08-01 14h17 +00:00 cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386).
6.1
Medium
CVE-2018-20949 2019-08-01 14h17 +00:00 cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385).
6.1
Medium
CVE-2018-20948 2019-08-01 14h16 +00:00 cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383).
6.1
Medium
CVE-2018-20947 2019-08-01 14h15 +00:00 cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356).
5.5
Medium
CVE-2018-20946 2019-08-01 14h14 +00:00 cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
3.3
Low
CVE-2018-20945 2019-08-01 14h13 +00:00 bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354).
5.7
Medium
CVE-2018-20944 2019-08-01 14h12 +00:00 cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
3.3
Low
CVE-2018-20943 2019-08-01 14h11 +00:00 cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).
2.5
Low
CVE-2018-20942 2019-08-01 14h11 +00:00 cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).
2.5
Low
CVE-2018-20940 2019-08-01 14h09 +00:00 cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342).
3.3
Low
CVE-2018-20939 2019-08-01 14h08 +00:00 cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).
3.3
Low
CVE-2018-20937 2019-08-01 14h06 +00:00 cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321).
4.3
Medium
CVE-2018-20936 2019-08-01 14h05 +00:00 cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308).
3.3
Low
CVE-2018-20923 2019-08-01 12h52 +00:00 cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
6.1
Medium
CVE-2018-20922 2019-08-01 12h51 +00:00 cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
6.1
Medium
CVE-2018-20921 2019-08-01 12h50 +00:00 cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
6.1
Medium
CVE-2018-20920 2019-08-01 12h49 +00:00 cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
6.1
Medium
CVE-2018-20919 2019-08-01 12h49 +00:00 cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
6.1
Medium
CVE-2018-20918 2019-08-01 12h48 +00:00 cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
6.1
Medium
CVE-2018-20917 2019-08-01 12h47 +00:00 cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
5.5
Medium
CVE-2018-20916 2019-08-01 12h46 +00:00 cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
5.4
Medium
CVE-2018-20915 2019-08-01 12h45 +00:00 cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
5.4
Medium
CVE-2018-20914 2019-08-01 12h44 +00:00 In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
7.3
High
CVE-2018-20913 2019-08-01 12h43 +00:00 cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
4.9
Medium
CVE-2018-20912 2019-08-01 12h42 +00:00 cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
6.3
Medium
CVE-2018-20911 2019-08-01 12h41 +00:00 cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).
7.2
High
CVE-2018-20910 2019-08-01 12h32 +00:00 cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357).
6.1
Medium
CVE-2018-20903 2019-08-01 12h21 +00:00 cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421).
6.1
Medium
CVE-2018-20902 2019-08-01 12h21 +00:00 cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408).
5.5
Medium
CVE-2018-20901 2019-08-01 12h20 +00:00 cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400).
6.1
Medium
CVE-2018-20887 2019-08-01 11h03 +00:00 cPanel before 74.0.0 allows SQL injection during database backups (SEC-420).
9.8
Critical
CVE-2018-20885 2019-08-01 11h00 +00:00 cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
5.3
Medium
CVE-2018-20884 2019-08-01 10h58 +00:00 cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367).
5.4
Medium
CVE-2018-20883 2019-08-01 10h56 +00:00 cPanel before 74.0.8 allows FTP access during account suspension (SEC-449).
6.5
Medium
CVE-2018-20881 2019-08-01 10h54 +00:00 cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446).
5.4
Medium
CVE-2018-20880 2019-08-01 10h53 +00:00 cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445).
3.3
Low
CVE-2018-20879 2019-08-01 10h52 +00:00 cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
6.3
Medium
CVE-2018-20878 2019-08-01 10h44 +00:00 cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
5.4
Medium
CVE-2018-20877 2019-08-01 10h44 +00:00 cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
5.4
Medium
CVE-2018-20876 2019-08-01 10h43 +00:00 cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
5.4
Medium
CVE-2018-20875 2019-08-01 10h41 +00:00 cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
5.4
Medium
CVE-2018-20870 2019-07-30 12h29 +00:00 The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467).
5.5
Medium
CVE-2018-20869 2019-07-30 12h27 +00:00 cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465).
7.8
High
CVE-2018-20862 2019-07-30 12h26 +00:00 cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366).
7.8
High
CVE-2018-20868 2019-07-30 12h25 +00:00 cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
6.1
Medium
CVE-2018-20866 2019-07-30 12h22 +00:00 cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461).
6.1
Medium
CVE-2018-20865 2019-07-30 12h22 +00:00 cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
6.1
Medium
CVE-2018-20864 2019-07-30 12h21 +00:00 cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454).
6.5
Medium
CVE-2018-20863 2019-07-30 12h20 +00:00 cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
9.8
Critical
CVE-2019-14414 2019-07-30 12h20 +00:00 In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478).
3.3
Low
CVE-2019-14413 2019-07-30 12h19 +00:00 cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476).
4.3
Medium
CVE-2019-14412 2019-07-30 12h18 +00:00 Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474).
3.3
Low
CVE-2019-14411 2019-07-30 12h18 +00:00 cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473).
5.3
Medium
CVE-2019-14410 2019-07-30 12h17 +00:00 Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472).
3.3
Low
CVE-2019-14409 2019-07-30 12h16 +00:00 cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466).
5.5
Medium
CVE-2019-14408 2019-07-30 12h15 +00:00 cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460).
4.3
Medium
CVE-2019-14407 2019-07-30 12h14 +00:00 cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415).
2.7
Low
CVE-2019-14406 2019-07-30 12h13 +00:00 cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493).
6.1
Medium
CVE-2019-14405 2019-07-30 12h12 +00:00 cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487).
8.8
High
CVE-2019-14404 2019-07-30 12h12 +00:00 cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484).
5.5
Medium
CVE-2019-14403 2019-07-30 12h10 +00:00 cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483).
4.3
Medium
CVE-2019-14402 2019-07-30 12h10 +00:00 cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481).
3.3
Low
CVE-2019-14401 2019-07-30 12h08 +00:00 cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480).
8.8
High
CVE-2019-14400 2019-07-30 12h08 +00:00 cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479).
7.8
High
CVE-2019-14399 2019-07-30 12h07 +00:00 The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477).
7.1
High
CVE-2019-14398 2019-07-30 12h06 +00:00 cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498).
8.8
High
CVE-2019-14397 2019-07-30 12h05 +00:00 cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496).
5.3
Medium
CVE-2019-14396 2019-07-30 12h04 +00:00 API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495).
3.3
Low
CVE-2019-14395 2019-07-30 12h03 +00:00 cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494).
3.3
Low
CVE-2019-14394 2019-07-30 12h03 +00:00 cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489).
5.5
Medium
CVE-2019-14393 2019-07-30 12h02 +00:00 cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486).
5.3
Medium
CVE-2019-14392 2019-07-30 12h00 +00:00 cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
8.8
High
CVE-2018-20867 2019-07-30 11h59 +00:00 cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
6.1
Medium
CVE-2019-14391 2019-07-30 10h48 +00:00 cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514).
3.3
Low
CVE-2019-14390 2019-07-30 10h47 +00:00 cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
5.4
Medium
CVE-2019-14389 2019-07-30 10h46 +00:00 cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510).
7.8
High
CVE-2019-14388 2019-07-30 10h45 +00:00 cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507).
7.5
High
CVE-2019-14387 2019-07-30 10h43 +00:00 cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506).
6.1
Medium
CVE-2019-14386 2019-07-30 10h38 +00:00 cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504).
5.4
Medium
CVE-2018-16236 2018-08-30 20h00 +00:00 cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering.
6.1
Medium
CVE-2008-6926 2009-08-10 18h00 +00:00 Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the scriptpath_show parameter in a GoAhead action. NOTE: this issue only crosses privilege boundaries when security settings such as disable_functions and safe_mode are active, since exploitation requires uploading of executable code to a home directory.
6.8
CVE-2008-6927 2009-08-10 18h00 +00:00 Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote attackers to inject arbitrary web script or HTML via the (1) localapp, (2) updatedir, (3) scriptpath_show, (4) domain_show, (5) thispage, (6) thisapp, and (7) currentversion parameters in an Upgrade action.
4.3
CVE-2009-2275 2009-07-01 10h26 +00:00 Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter.
5
CVE-2006-2825 2006-06-05 15h00 +00:00 cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive.
5.1
CVE-2006-1119 2006-03-09 19h00 +00:00 fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message.
4
CVE-2006-0763 2006-02-18 01h00 +00:00 Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter.
4.3