Vulnerability index

Browse CVEs

322 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cpanel MEDIUM 6.3
CVE-2017-18468

cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).

Fix: 56.0.46 / 58.0.45+
Fix from $1,600 2019-08-05
Cpanel HIGH 7.8
CVE-2017-18460

cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).

Fix: 60.0.39 / 62.0.17+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18463

cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).

Fix: 56.0.46 / 58.0.45+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18459

cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).

Fix: 56.0.46 / 58.0.45+
Fix from $1,950 2019-08-02
Cpanel MEDIUM 6.7
CVE-2017-18452

cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.1
CVE-2017-18456

cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).

Fix: 56.0.46 / 58.0.45+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.5
CVE-2017-18449

cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.4
CVE-2017-18454

cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.3
CVE-2017-18448

cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.3
CVE-2017-18451

cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.3
CVE-2017-18438

cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.3
CVE-2017-18439

cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.3
CVE-2017-18446

cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 6.3
CVE-2017-18447

cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.8
CVE-2017-18443

cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.3
CVE-2017-18442

cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.3
CVE-2017-18444

cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.0
CVE-2017-18441

cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).

Fix: 56.0.49 / 58.0.49+
Fix from $1,600 2019-08-02
Cpanel HIGH 7.3
CVE-2017-18435

cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).

Fix: 56.0.49 / 58.0.49+
Fix from $1,950 2019-08-02
Cpanel HIGH 8.8
CVE-2017-18433

cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).

Fix: 56.0.49 / 58.0.49+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18432

In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).

Fix: 56.0.49 / 58.0.49+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18434

cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).

Fix: 56.0.49 / 58.0.49+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.5
CVE-2017-18431

cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).

Fix: 66.0.1+
Fix from $1,950 2019-08-02
Cpanel MEDIUM 5.4
CVE-2017-18417

cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).

Fix: 66.0.2+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.4
CVE-2017-18418

cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).

Fix: 66.0.2+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.4
CVE-2017-18419

cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).

Fix: 66.0.2+
Fix from $1,600 2019-08-02
Cpanel MEDIUM 5.4
CVE-2017-18420

cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).

Fix: 66.0.2+
Fix from $1,600 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18413

In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).

Fix: 56.0.52 / 60.0.48+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.8
CVE-2017-18415

cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).

Fix: 56.0.52 / 60.0.48+
Fix from $1,950 2019-08-02
Cpanel HIGH 7.5
CVE-2017-18406

cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).

Fix: 64.0.40 / 66.0.23+
Fix from $1,950 2019-08-02