|
249171
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.4 allows self XSS on the webmail Password and Security page (SEC-199).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18473
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249172
|
6.1 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.4 allows reflected XSS in reset-password interfaces (SEC-198).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18472
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249173
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.4 allows self XSS on the paper_lantern password-change screen (SEC-197).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18471
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249174
|
8.8 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.4 has a fixed password for the Munin MySQL test account (SEC-196).
|
CWE-255
Credentials Management
|
CVE-2017-18470
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249175
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows demo accounts to execute code via an NVData_fetchinc API call (SEC-233).
|
CWE-20
Improper Input Validation
|
CVE-2017-18469
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249176
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
|
CWE-94
Code Injection
|
CVE-2017-18468
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249177
|
4.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows access to restricted resources because of a URL filtering error (SEC-229).
|
CWE-254
7PK - Security Features
|
CVE-2017-18467
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249178
|
2.7 |
LOW
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 does not properly recognize domain ownership during addition of parked domains to a mail configuration (SEC-228).
|
CWE-20
Improper Input Validation
|
CVE-2017-18466
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249179
|
4.4 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 62.0.17 does not have a sufficient list of reserved usernames (SEC-227).
|
CWE-20
Improper Input Validation
|
CVE-2017-18465
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249180
|
4.9 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 62.0.17 allows arbitrary file-overwrite operations via the WHM Zone Template editor (SEC-226).
|
CWE-20
Improper Input Validation
|
CVE-2017-18464
|
2024-11-21 12:20 |
2019-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|