|
250471
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).
|
CWE-20
Improper Input Validation
|
CVE-2017-18469
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250472
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
|
CWE-94
Code Injection
|
CVE-2017-18468
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250473
|
4.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).
|
CWE-254
7PK - Security Features
|
CVE-2017-18467
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250474
|
2.7 |
LOW
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228).
|
CWE-20
Improper Input Validation
|
CVE-2017-18466
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250475
|
4.4 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).
|
CWE-20
Improper Input Validation
|
CVE-2017-18465
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250476
|
4.9 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).
|
CWE-20
Improper Input Validation
|
CVE-2017-18464
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250477
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows a CPHulk one-day ban bypass when IP based protection is enabled (SEC-224).
|
CWE-254
7PK - Security Features
|
CVE-2017-18462
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250478
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows code execution in the context of the root account via a long DocumentRoot path (SEC-225).
|
CWE-20
Improper Input Validation
|
CVE-2017-18463
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250479
|
4.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows does not preserve security policy questions across an account rename (SEC-223).
|
CWE-20
Improper Input Validation
|
CVE-2017-18461
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250480
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
|
CWE-20
Improper Input Validation
|
CVE-2017-18460
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|