|
249361
|
5.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18451
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249362
|
4.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18450
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249363
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).
|
CWE-20
Improper Input Validation
|
CVE-2017-18449
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249364
|
5.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
|
CWE-22
Path Traversal
|
CVE-2017-18448
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249365
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).
|
CWE-20
Improper Input Validation
|
CVE-2017-18447
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249366
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2017-18446
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249367
|
4.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).
|
CWE-254
7PK - Security Features
|
CVE-2017-18445
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249368
|
5.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
|
CWE-20
Improper Input Validation
|
CVE-2017-18444
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249369
|
5.8 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).
|
CWE-20
Improper Input Validation
|
CVE-2017-18443
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249370
|
5.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
|
CWE-77
Command Injection
|
CVE-2017-18442
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|