CVEs (417)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
cPanel before 80.0.5 allows local code execution in the context of a different cPanel account because of insecure cpphp execution (SEC-486). |
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). |
cPanel before 76.0.8 allows arbitrary code execution in the context of the root account via dnssec adminbin (SEC-465). |
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464). |
cPanel before 76.0.8 has Stored XSS in the WHM "Reset a DNS Zone" feature (SEC-461). |
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459). |
cPanel before 76.0.8 allows a persistent Virtual FTP accounts after removal of its associated domain (SEC-454). |
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452). |
cPanel before 76.0.8 unsafely performs PostgreSQL password changes (SEC-366). |
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501). |
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462). |
cPanel before 82.0.2 does not properly enforce Reseller package creation ACLs (SEC-514). |
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512). |
cPanel before 82.0.2 allows local users to discover the MySQL root password (SEC-510). |
cPanel before 82.0.2 allows unauthenticated file creation because Exim log parsing is mishandled (SEC-507). |
cPanel before 82.0.2 has Self XSS in the cPanel and webmail master templates (SEC-506). |
cPanel before 82.0.2 has stored XSS in the WHM Tomcat Manager interface (SEC-504). |
cPanel through 74 allows XSS via a crafted filename in the logs subdirectory of a user account, because the filename is mishandled during frontend/THEME/raw/index.html rendering. |
Open redirect vulnerability in cgiemail and cgiecho allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via vectors involving the (1) success or (2) failure parameter. |
Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter. |