|
249231
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18413
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249232
|
2.5 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-18412
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249233
|
6.8 |
MEDIUM
Network
|
cpanel
|
cpanel
|
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
|
CWE-20
Improper Input Validation
|
CVE-2017-18411
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249234
|
6.5 |
MEDIUM
Network
|
cpanel
|
cpanel
|
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
|
CWE-20
Improper Input Validation
|
CVE-2017-18410
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249235
|
6.5 |
MEDIUM
Network
|
cpanel
|
cpanel
|
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
|
CWE-20
Improper Input Validation
|
CVE-2017-18409
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249236
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18408
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249237
|
4.8 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2017-18407
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249238
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
|
CWE-89
SQL Injection
|
CVE-2017-18406
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249239
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).
|
CWE-20
Improper Input Validation
|
CVE-2017-18405
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249240
|
3.1 |
LOW
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).
|
CWE-284
Improper Access Control
|
CVE-2017-18404
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|