|
249401
|
6.8 |
MEDIUM
Network
|
cpanel
|
cpanel
|
The "addon domain conversion" feature in cPanel before 67.9999.103 can copy all MySQL databases to the new account (SEC-285).
|
CWE-20
Improper Input Validation
|
CVE-2017-18411
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249402
|
6.5 |
MEDIUM
Network
|
cpanel
|
cpanel
|
In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284).
|
CWE-20
Improper Input Validation
|
CVE-2017-18410
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249403
|
6.5 |
MEDIUM
Network
|
cpanel
|
cpanel
|
In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283).
|
CWE-20
Improper Input Validation
|
CVE-2017-18409
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249404
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18408
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249405
|
4.8 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279).
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2017-18407
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249406
|
7.5 |
HIGH
Network
|
cpanel
|
cpanel
|
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
|
CWE-89
SQL Injection
|
CVE-2017-18406
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249407
|
5.5 |
MEDIUM
Local
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345).
|
CWE-20
Improper Input Validation
|
CVE-2017-18405
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249408
|
3.1 |
LOW
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows domain data to be deleted for domains with the .lock TLD (SEC-341).
|
CWE-284
Improper Access Control
|
CVE-2017-18404
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249409
|
6.3 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows code execution in the context of the nobody account via Mailman archives (SEC-337).
|
CWE-284
Improper Access Control
|
CVE-2017-18403
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249410
|
5.4 |
MEDIUM
Network
|
cpanel
|
cpanel
|
cPanel before 68.0.15 allows stored XSS during a cpaddons moderated upgrade (SEC-336).
|
CWE-79
Cross-site Scripting
|
CVE-2017-18402
|
2024-11-21 12:20 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|