Product:

Cpanel

(Cpanel)
Repositories

Unknown:

This might be proprietary software.

#Vulnerabilities 415
Date Id Summary Products Score Patch Annotated
2019-08-02 CVE-2017-18410 In cPanel before 67.9999.103, a user account's backup archive could contain all MySQL databases on the server (SEC-284). Cpanel 6.5
2019-08-02 CVE-2017-18409 In cPanel before 67.9999.103, the backup interface could return a backup archive with all MySQL databases (SEC-283). Cpanel 6.5
2019-08-02 CVE-2017-18408 cPanel before 67.9999.103 allows stored XSS in WHM MySQL Password Change interfaces (SEC-282). Cpanel 5.4
2019-08-02 CVE-2017-18407 cPanel before 67.9999.103 does not enforce SSL hostname verification for the support-agreement download (SEC-279). Cpanel 4.8
2019-08-02 CVE-2017-18406 cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276). Cpanel 7.5
2019-08-02 CVE-2017-18405 cPanel before 68.0.15 allows arbitrary file-read operations because of the backup .htaccess modification logic (SEC-345). Cpanel 5.5
2019-08-02 CVE-2017-18394 cPanel before 68.0.15 does not have a sufficient list of reserved usernames (SEC-327). Cpanel 2.7
2019-08-02 CVE-2017-18393 cPanel before 68.0.15 does not block a username of postmaster, which might allow reception of private e-mail (SEC-326). Cpanel 2.7
2019-08-02 CVE-2017-18392 cPanel before 68.0.15 allows collisions because PostgreSQL databases can be assigned to multiple accounts (SEC-325). Cpanel 2.0
2019-08-02 CVE-2017-18387 cPanel before 68.0.15 allows arbitrary code execution via Maketext injection in a Reseller style upload (SEC-314). Cpanel 7.2