CVE ID | Published | Description | Score | Severity |
---|---|---|---|---|
The WHM Locale Upload feature in cPanel before 98.0.1 allows XXE attacks (SEC-585). | 7.2 |
High |
||
The WHM Locale Upload feature in cPanel before 98.0.1 allows unserialization attacks (SEC-585). | 7.2 |
High |
||
In cPanel before 96.0.13, scripts/fix-cpanel-perl mishandles the creation of temporary files (SEC-586). | 7.5 |
High |
||
In cPanel before 96.0.13, fix_cpanel_perl lacks verification of the integrity of downloads (SEC-587). | 8.1 |
High |
||
cPanel before 94.0.3 allows self-XSS via EasyApache 4 Save Profile (SEC-581). | 6.1 |
Medium |
||
cPanel before 92.0.9 allows a Reseller to bypass the suspension lock (SEC-578). | 7.5 |
High |
||
cPanel before 92.0.9 allows a MySQL user (who has an old-style password hash) to bypass suspension (SEC-579). | 7.5 |
High |
||
cPanel before 90.0.17 allows self-XSS via the WHM Transfer Tool interface (SEC-577). | 6.1 |
Medium |
||
cPanel before 90.0.17 has multiple instances of URL parameter injection (SEC-567). | 4.1 |
Medium |
||
cPanel before 88.0.3 mishandles the Exim filter path, leading to remote code execution (SEC-485). | 9.8 |
Critical |
||
cPanel before 88.0.3 allows attackers to bypass the SMTP greylisting protection mechanism (SEC-491). | 7.5 |
High |
||
chsh in cPanel before 88.0.3 allows a Jailshell escape (SEC-497). | 9.8 |
Critical |
||
In cPanel before 88.0.3, insecure RNDC credentials are used for BIND on a templated VM (SEC-549). | 9.8 |
Critical |
||
In cPanel before 88.0.3, an insecure auth policy API key is used by Dovecot on a templated VM (SEC-550). | 7.5 |
High |
||
In cPanel before 88.0.3, an insecure site password is used for Mailman on a templated VM (SEC-551). | 7.5 |
High |
||
In cPanel before 88.0.3, an insecure SRS secret is used on a templated VM (SEC-552). | 7.5 |
High |
||
In cPanel before 88.0.3, insecure chkservd test credentials are used on a templated VM (SEC-554). | 9.8 |
Critical |
||
cPanel before 88.0.3 has weak permissions (world readable) for the proxy subdomains log file (SEC-558). | 7.5 |
High |
||
cPanel before 88.0.3, upon an upgrade, establishes predictable PowerDNS API keys (SEC-561). | 7.5 |
High |
||
cPanel before 88.0.13 mishandles file-extension dispatching, leading to code execution (SEC-488). | 9.8 |
Critical |
||
cPanel before 88.0.13 allows bypass of a protection mechanism that attempted to restrict package modification (SEC-557). | 7.5 |
High |
||
cPanel before 88.0.13 allows self XSS via DNS Zone Manager DNSSEC interfaces (SEC-564). | 6.1 |
Medium |
||
cPanel before 90.0.10 allows self XSS via the WHM Edit DNS Zone interface (SEC-566). | 6.1 |
Medium |
||
The email quota cache in cPanel before 90.0.10 allows overwriting of files. | 7.5 |
High |
||
cPanel before 90.0.10 allows self XSS via WHM Manage API Tokens interfaces (SEC-569). | 6.1 |
Medium |
||
cPanel before 90.0.10 allows self XSS via the Cron Jobs interface (SEC-573). | 6.1 |
Medium |
||
cPanel before 90.0.10 allows self XSS via the Cron Editor interface (SEC-574). | 6.1 |
Medium |
||
cPanel before 84.0.20 allows resellers to achieve remote code execution as root via a cpsrvd rsync shell (SEC-545). | 7.2 |
High |
||
cPanel before 84.0.20 allows a demo account to achieve remote code execution via a cpsrvd rsync shell (SEC-544). | 9.8 |
Critical |
||
cPanel before 82.0.15 allows self XSS in the WHM Update Preferences interface (SEC-528). | 6.1 |
Medium |
||
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345). | 5.5 |
Medium |
||
cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341). | 3.1 |
Low |
||
cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337). | 6.3 |
Medium |
||
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336). | 5.4 |
Medium |
||
cPanel before 68.0.15 allows user accounts to be partially created with invalid username formats (SEC-334). | 2.7 |
Low |
||
cPanel before 68.0.15 allows local root code execution via cpdavd (SEC-333). | 7.8 |
High |
||
cPanel before 68.0.15 allows attackers to read root's crontab file during a short time interval upon enabling or disabling sqloptimizer (SEC-332). | 3.7 |
Low |
||
DnsUtils in cPanel before 68.0.15 allows zone creation for hostname and account subdomains (SEC-331). | 3.8 |
Low |
||
cPanel before 68.0.15 does not preserve permissions for local backup transport (SEC-330). | 3.3 |
Low |
||
cPanel before 68.0.15 allows arbitrary file-read operations via Exim vdomainaliases (SEC-329). | 5.5 |
Medium |
||
cPanel before 68.0.15 does not block a username of ssl (SEC-328). | 2.7 |
Low |
||
cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327). | 2.7 |
Low |
||
cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326). | 2.7 |
Low |
||
cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325). | 2 |
Low |
||
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323). | 2.5 |
Low |
||
cPanel before 68.0.15 allows code execution in the context of the root account because of weak permissions on incremental backups (SEC-322). | 7.8 |
High |
||
cPanel before 68.0.15 allows string format injection in dovecot-xaps-plugin (SEC-318). | 6.3 |
Medium |
||
cPanel before 68.0.15 can perform unsafe file operations because Jailshell does not set the umask (SEC-315). | 7.8 |
High |
||
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314). | 7.2 |
High |
||
cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in PostgresAdmin (SEC-313). | 7.2 |
High |
||
cPanel before 68.0.15 allows unprivileged users to access restricted directories during account restores (SEC-311). | 5.5 |
Medium |
||
cPanel before 68.0.15 allows jailed accounts to restore files that are outside of the jail (SEC-310). | 3.8 |
Low |
||
cPanel before 68.0.15 writes home-directory backups to an incorrect location (SEC-309). | 7.8 |
High |
||
cPanel before 68.0.15 allows use of an unreserved e-mail address in DNS zone SOA records (SEC-306). | 2.7 |
Low |
||
cPanel before 68.0.27 allows self XSS in the WHM listips interface (SEC-389). | 6.1 |
Medium |
||
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388). | 6.5 |
Medium |
||
cPanel before 68.0.27 allows self XSS in WHM Spamd Startup Config (SEC-387). | 6.1 |
Medium |
||
cPanel before 68.0.27 allows self stored XSS in WHM Account Transfer (SEC-386). | 6.1 |
Medium |
||
cPanel before 68.0.27 allows self XSS in WHM Apache Configuration Include Editor (SEC-385). | 6.1 |
Medium |
||
cPanel before 68.0.27 allows self XSS in cPanel Backup Restoration (SEC-383). | 6.1 |
Medium |
||
cPanel before 68.0.27 allows certain file-write operations via the telnetcrt script (SEC-356). | 5.5 |
Medium |
||
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355). | 3.3 |
Low |
||
bin/csvprocess in cPanel before 68.0.27 allows insecure file operations (SEC-354). | 5.7 |
Medium |
||
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353). | 3.3 |
Low |
||
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352). | 2.5 |
Low |
||
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351). | 2.5 |
Low |
||
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349). | 5.6 |
Medium |
||
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon the enabling of backups (SEC-342). | 3.3 |
Low |
||
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339). | 3.3 |
Low |
||
cPanel before 68.0.27 does not enforce ownership during addpkgext and delpkgext WHM API calls (SEC-324). | 2.7 |
Low |
||
cPanel before 68.0.27 does not validate database and dbuser names during renames (SEC-321). | 4.3 |
Medium |
||
cPanel before 68.0.27 allows attackers to read the SRS secret via exim.conf (SEC-308). | 3.3 |
Low |
||
cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412). | 5.4 |
Medium |
||
cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411). | 6.5 |
Medium |
||
cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410). | 5.4 |
Medium |
||
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406). | 2.7 |
Low |
||
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405). | 6.3 |
Medium |
||
cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401). | 6.5 |
Medium |
||
cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391). | 6.1 |
Medium |
||
cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392). | 6.1 |
Medium |
||
cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382). | 3.8 |
Low |
||
cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380). | 6.7 |
Medium |
||
cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379). | 6.7 |
Medium |
||
cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378). | 5.5 |
Medium |
||
cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377). | 6.1 |
Medium |
||
cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376). | 6.1 |
Medium |
||
cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375). | 6.1 |
Medium |
||
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374). | 6.1 |
Medium |
||
cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373). | 6.1 |
Medium |
||
cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372). | 6.1 |
Medium |
||
cPanel before 70.0.23 allows any user to disable Solr (SEC-371). | 5.5 |
Medium |
||
cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370). | 5.4 |
Medium |
||
cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369). | 5.4 |
Medium |
||
In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368). | 7.3 |
High |
||
cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364). | 4.9 |
Medium |
||
cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362). | 6.3 |
Medium |
||
cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359). | 7.2 |
High |
||
cPanel before 70.0.23 allows self XSS in the WHM cPAddons showsecurity Interface (SEC-357). | 6.1 |
Medium |
||
cPanel before 70.0.23 allows arbitrary file-chmod operations during legacy incremental backups (SEC-338). | 7.1 |
High |
||
cPanel before 71.9980.37 allows arbitrary file-read operations during pkgacct custom template handling (SEC-435). | 5.5 |
Medium |
||
cPanel before 71.9980.37 does not enforce the Mime::list_hotlinks API feature restriction (SEC-432). | 4.3 |
Medium |
||
cPanel before 71.9980.37 allows attackers to make API calls that bypass the images feature restriction (SEC-430). | 4.3 |
Medium |
||
cPanel before 71.9980.37 allows attackers to make API calls that bypass the backup feature restriction (SEC-429). | 5.4 |
Medium |
||
cPanel before 71.9980.37 allows attackers to make API calls that bypass the cron feature restriction (SEC-427). | 4.3 |
Medium |
||
cPanel before 71.9980.37 allows self XSS in the WHM Backup Configuration interface (SEC-421). | 6.1 |
Medium |
||
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408). | 5.5 |
Medium |
||
cPanel before 71.9980.37 allows Remote-Stored XSS in WHM Save Theme Interface (SEC-400). | 6.1 |
Medium |
||
cPanel before 71.9980.37 allows stored XSS in the WHM cPAddons installation interface (SEC-398). | 6.1 |
Medium |
||
cPanel before 71.9980.37 allows e-mail injection during cPAddons moderation (SEC-396). | 4.3 |
Medium |
||
cPanel before 71.9980.37 allows arbitrary file-unlink operations via the cPAddons moderation system (SEC-395). | 2.8 |
Low |
||
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394). | 3.9 |
Low |
||
In cPanel before 71.9980.37, API tokens retain ACLs after those ACLs are removed from the corresponding accounts (SEC-393). | 7.2 |
High |
||
cPanel before 74.0.0 allows SQL injection during database backups (SEC-420). | 9.8 |
Critical |
||
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). | 5.3 |
Medium |
||
cPanel before 74.0.0 allows stored XSS in the WHM File Restoration interface (SEC-367). | 5.4 |
Medium |
||
cPanel before 74.0.8 allows FTP access during account suspension (SEC-449). | 6.5 |
Medium |
||
cPanel before 74.0.8 allows self stored XSS on the Security Questions login page (SEC-446). | 5.4 |
Medium |
||
cPanel before 74.0.8 mishandles account suspension because of an invalid email_accounts.json file (SEC-445). | 3.3 |
Low |
||
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444). | 6.3 |
Medium |
||
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441). | 5.4 |
Medium |
||
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437). | 5.4 |
Medium |
||
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434). | 5.4 |
Medium |
||
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433). | 5.4 |
Medium |
||
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). | 5.5 |
Medium |
||
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465). | 7.8 |
High |
||
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366). | 7.8 |
High |
||
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). | 6.1 |
Medium |
||
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). | 6.1 |
Medium |
||
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). | 6.1 |
Medium |
||
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). | 6.5 |
Medium |
||
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). | 9.8 |
Critical |
||
In cPanel before 78.0.2, a Userdata cache temporary file can conflict with domains (SEC-478). | 3.3 |
Low |
||
cPanel before 78.0.2 allows certain file-write operations as shared users during connection resets (SEC-476). | 4.3 |
Medium |
||
Maketext in cPanel before 78.0.2 allows format-string injection in the DCV check_domains_via_dns UAPI (SEC-474). | 3.3 |
Low |
||
cPanel before 78.0.2 does not properly restrict demo accounts from writing to files via the DCV UAPI (SEC-473). | 5.3 |
Medium |
||
Maketext in cPanel before 78.0.2 allows format-string injection in the Email store_filter UAPI (SEC-472). | 3.3 |
Low |
||
cPanel before 78.0.2 allows arbitrary file-read operations via Passenger adminbin (SEC-466). | 5.5 |
Medium |
||
cPanel before 78.0.2 allows a demo account to link with an OpenID provider (SEC-460). | 4.3 |
Medium |
||
cPanel before 78.0.2 reveals internal data to OpenID providers (SEC-415). | 2.7 |
Low |
||
cPanel before 78.0.18 has stored XSS in the BoxTrapper Queue Listing (SEC-493). | 6.1 |
Medium |
||
cPanel before 78.0.18 allows demo accounts to execute code via securitypolicy.cg (SEC-487). | 8.8 |
High |
||
cPanel before 78.0.18 allows certain file-read operations in the context of the root account via the Exim virtual_user_spam router (SEC-484). | 5.5 |
Medium |
||
cPanel before 78.0.18 offers an open mail relay because of incorrect domain-redirect routing (SEC-483). | 4.3 |
Medium |
||
cPanel before 78.0.18 unsafely determines terminal capabilities by using infocmp (SEC-481). | 3.3 |
Low |
||
cPanel before 78.0.18 allows code execution via an addforward API1 call (SEC-480). | 8.8 |
High |
||
cPanel before 78.0.18 allows local users to escalate to root access because of userdata cache misparsing (SEC-479). | 7.8 |
High |
||
The SSL certificate-storage feature in cPanel before 78.0.18 allows unsafe file operations in the context of the root account (SEC-477). | 7.1 |
High |
||
cPanel before 80.0.5 allows demo accounts to execute arbitrary code via ajax_maketext_syntax_util.pl (SEC-498). | 8.8 |
High |
||
cPanel before 80.0.5 allows demo accounts to modify arbitrary files via the extractfile API1 call (SEC-496). | 5.3 |
Medium |
||
API Analytics adminbin in cPanel before 80.0.5 allows spoofed insertions of log data (SEC-495). | 3.3 |
Low |
||
cPanel before 80.0.5 uses world-readable permissions for the Queueprocd log (SEC-494). | 3.3 |
Low |
||
cPanel before 80.0.5 allows unsafe file operations in the context of the root account via the fetch_ssl_certificates_for_fqdns API (SEC-489). | 5.5 |
Medium |
||
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486). | 5.3 |
Medium |
||
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501). | 8.8 |
High |
||
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462). | 6.1 |
Medium |
||
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514). | 3.3 |
Low |
||
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512). | 5.4 |
Medium |
||
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510). | 7.8 |
High |
||
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507). | 7.5 |
High |
||
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506). | 6.1 |
Medium |
||
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504). | 5.4 |
Medium |
||
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering. | 6.1 |
Medium |
||
Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the scriptpath_show parameter in a GoAhead action. NOTE: this issue only crosses privilege boundaries when security settings such as disable_functions and safe_mode are active, since exploitation requires uploading of executable code to a home directory. | 6.8 |
|||
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel allow remote attackers to inject arbitrary web script or HTML via the (1) localapp, (2) updatedir, (3) scriptpath_show, (4) domain_show, (5) thispage, (6) thisapp, and (7) currentversion parameters in an Upgrade action. | 4.3 |
|||
Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in the domain parameter. | 5 |
|||
cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user's own open_basedir directive, but not the main server's open_basedir directive. | 5.1 |
|||
fantastico in Cpanel does not properly handle when it has insufficient permissions to perform certain file operations, which allows remote authenticated users to obtain the full pathname, which is leaked in a PHP error message. | 4 |
|||
Cross-site scripting (XSS) vulnerability in dowebmailforward.cgi in cPanel allows remote attackers to inject arbitrary web script or HTML via a URL encoded value in the fwd parameter. | 4.3 |