Vulnerability index

Browse CVEs

322 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Whm MEDIUM 5.4
CVE-2017-11441

The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.…

Fix: after 56.0.50
Fix from $1,600 2017-07-19
Cgiecho MEDIUM 6.1
CVE-2017-5616

Cross-site scripting (XSS) vulnerability in cgiemail and cgiecho allows remote attackers to inject arbitrary web script or HTML via the addendum para…

Mitigation only
Fix from $1,600 2017-03-03
Cgiecho HIGH 7.8
CVE-2017-5613

Format string vulnerability in cgiemail and cgiecho allows remote attackers to execute arbitrary code via format string specifiers in a template file.

Mitigation only
Fix from $1,950 2017-03-03
Cpanel MEDIUM 6.1
CVE-2017-5614

Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via…

Fix: 11.54.0.36 / 56.0.43+
Fix from $1,600 2017-03-03
Cgiecho MEDIUM 6.1
CVE-2017-5615

cgiemail and cgiecho allow remote attackers to inject HTTP headers via a newline character in the redirect location.

Mitigation only
Fix from $1,600 2017-03-03
Cpanel MEDIUM 5.0
CVE-2008-7142

Absolute path traversal vulnerability in the Disk Usage module (frontend/x/diskusage/index.html) in cPanel 11.18.3 allows remote attackers to list ar…

No fix yet
Fix from $1,600 2009-09-01
Cpanel MEDIUM 5.0
CVE-2009-2275

Directory traversal vulnerability in frontend/x3/stats/lastvisit.html in cPanel allows remote attackers to read arbitrary files via a .. (dot dot) in…

No fix yet
Fix from $1,600 2009-07-01
Cpanel HIGH 8.5
CVE-2008-2478

scripts/wwwacct in cPanel 11.18.6 STABLE and earlier and 11.23.1 CURRENT and earlier allows remote authenticated users with reseller privileges to ex…

Fix: after 11.23.1
Fix from $1,950 2008-05-28
Cpanel HIGH 7.8
CVE-2007-3367

Simple CGI Wrapper (scgiwrap) in cPanel before 10.9.1, and 11.x before 11.4.19-R14378, allows remote attackers to obtain sensitive information via a …

Fix: after 11.4.19
Fix from $1,950 2007-06-22
Webhost Manager HIGH 7.5
CVE-2007-0854EPSS 6%

Remote file inclusion vulnerability in scripts2/objcache in cPanel WebHost Manager (WHM) allows remote attackers to execute arbitrary code via a URL …

No fix yet
Fix from $1,950 2007-02-08
Cpanel MEDIUM 6.8
CVE-2006-6523

Cross-site scripting (XSS) vulnerability in mail/manage.html in BoxTrapper in cPanel 11 allows remote attackers to inject arbitrary web script or HTM…

No fix yet
Fix from $1,600 2006-12-14
Webhost Manager MEDIUM 6.0
CVE-2006-6198

Multiple cross-site scripting (XSS) vulnerabilities in cPanel WebHost Manager (WHM) 3.1.0 allow remote authenticated users to inject arbitrary web sc…

No fix yet
Fix from $1,600 2006-12-01
Cpanel HIGH 8.8
CVE-2006-5014

Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqlad…

Patch available
Fix from $1,950 2006-09-27
Cpanel MEDIUM 5.1
CVE-2006-2825

cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical …

No fix yet
Fix from $1,600 2006-06-05
Cpanel MEDIUM 5.5
CVE-2004-1603

cPanel 9.4.1-RELEASE-64 follows hard links, which allows local users to (1) read arbitrary files via the backup feature or (2) chown arbitrary files …

Patch available
Fix from $1,600 2004-10-18
Cpanel MEDIUM 5.0
CVE-2004-1604

cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created wh…

Mitigation only
Fix from $1,600 2004-09-30
Cpanel HIGH 7.2
CVE-2004-0490

cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use th…

No fix yet
Fix from $1,950 2004-08-18
Cpanel HIGH 9.3
CVE-2004-1875

Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote attackers to inject arbitrary web script or HTML via the (1) ema…

Patch available
Fix from $1,950 2004-03-30
Cpanel HIGH 10.0
CVE-2004-1769EPSS 35%

The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x, allows remote attackers to ex…

No fix yet
Fix from $1,950 2004-03-11
Cpanel HIGH 10.0
CVE-2004-1770EPSS 10%

The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shell metacharacters in the user …

Patch available
Fix from $1,950 2004-03-11
Cpanel HIGH 10.0
CVE-2003-1425EPSS 11%

guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.

No fix yet
Fix from $1,950 2003-12-31
Cpanel MEDIUM 6.8
CVE-2003-0521

Cross-site scripting (XSS) vulnerability in cPanel 6.4.2 allows remote attackers to insert arbitrary HTML and possibly gain cPanel administrator priv…

Mitigation only
Fix from $1,600 2003-08-18