|
249391
|
3.3 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
|
CWE-284
Improper Access Control
|
CVE-2017-18421
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249392
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18420
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249393
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18419
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249394
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18418
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249395
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18417
|
2024-11-21 12:20 |
2019-08-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249396
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 allows arbitrary file-overwrite operations during a Roundcube SQLite schema update (SEC-303).
|
CWE-284
Improper Access Control
|
CVE-2017-18416
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249397
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 allows code execution in the context of the mailman account because of incorrect environment-variable filtering (SEC-302).
|
CWE-20
Improper Input Validation
|
CVE-2017-18415
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249398
|
7.4 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 allows an open redirect in /unprotected/redirect.html (SEC-300).
|
CWE-601
Open Redirect
|
CVE-2017-18414
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249399
|
7.8 |
HIGH
Local
|
cpanel
|
cpanel
|
In cPanel before 67.9999.103, the backup system overwrites root's home directory when a mount disappears (SEC-299).
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18413
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249400
|
2.5 |
LOW
Local
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 allows Apache HTTP Server log files to become world-readable because of mishandling on an account rename (SEC-296).
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-18412
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|