|
249191
|
4.9 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
|
CWE-20
Improper Input Validation
|
CVE-2017-18453
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249192
|
6.7 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
|
CWE-20
Improper Input Validation
|
CVE-2017-18452
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249193
|
5.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18451
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249194
|
4.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18450
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249195
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).
|
CWE-20
Improper Input Validation
|
CVE-2017-18449
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249196
|
5.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
|
CWE-22
Path Traversal
|
CVE-2017-18448
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249197
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).
|
CWE-20
Improper Input Validation
|
CVE-2017-18447
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249198
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-18446
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249199
|
4.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).
|
CWE-254
7PK - Security Features
|
CVE-2017-18445
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249200
|
5.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
|
CWE-20
Improper Input Validation
|
CVE-2017-18444
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|