CVE-2017-18460
Last Modified: 21 Nov 2024cPanel before 62.0.17 allows arbitrary code execution during automatic SSL installation (SEC-221).
CVE-2017-18459
Last Modified: 21 Nov 2024cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
CVE-2017-18458
Last Modified: 21 Nov 2024cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
CVE-2017-18457
Last Modified: 21 Nov 2024cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218).
CVE-2017-18456
Last Modified: 21 Nov 2024cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
CVE-2017-18455
Last Modified: 21 Nov 2024In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).
CVE-2017-18454
Last Modified: 21 Nov 2024cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
CVE-2017-18453
Last Modified: 21 Nov 2024cPanel before 64.0.21 does not preserve supplemental groups across account renames (SEC-260).
CVE-2017-18452
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
CVE-2017-18451
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows attackers to read a user's crontab file during a short time interval upon a cPAddon upgrade (SEC-257).
CVE-2017-18450
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
CVE-2017-18449
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows certain file-rename operations in the context of the root account via scripts/convert_roundcube_mysql2sqlite (SEC-254).
CVE-2017-18448
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows certain file-read operations via a Serverinfo_manpage API call (SEC-252).
CVE-2017-18447
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo accounts to execute code via the ClamScanner_getsocket API (SEC-251).
CVE-2017-18446
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows file-read and file-write operations for demo accounts via the SourceIPCheck API (SEC-250).
CVE-2017-18445
Last Modified: 21 Nov 2024cPanel before 64.0.21 does not enforce demo restrictions for SSL API calls (SEC-249).
CVE-2017-18444
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo accounts to execute SSH API commands (SEC-248).
CVE-2017-18443
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo and suspended accounts to use SSH port forwarding (SEC-247).
CVE-2017-18442
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo accounts to execute Cpanel::SPFUI API commands (SEC-246).
CVE-2017-18441
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo accounts to redirect web traffic (SEC-245).
CVE-2017-18440
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
CVE-2017-18439
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo accounts to execute code via an ImageManager_dimensions API call (SEC-243).
CVE-2017-18438
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo accounts to execute code via Encoding API calls (SEC-242).
CVE-2017-18437
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
CVE-2017-18436
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
CVE-2019-10961
Last Modified: 21 Nov 2024In Advantech WebAccess HMI Designer Version 2.1.9.23 and prior, processing specially crafted MCR files lacking proper validation of user supplied data may cause the system to write outside the intended buffer area, allowing remote code execution.
CVE-2017-18435
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows demo accounts to execute code via the BoxTrapper API (SEC-238).
CVE-2017-18434
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows code execution in the context of the root account via a SET_VHOST_LANG_PACKAGE multilang adminbin call (SEC-237).
CVE-2017-18433
Last Modified: 21 Nov 2024cPanel before 64.0.21 allows code execution by webmail and demo accounts via a store_filter API call (SEC-236).
CVE-2017-18432
Last Modified: 21 Nov 2024In cPanel before 64.0.21, Horde MySQL to SQLite conversion can leak a database password (SEC-234).
CVE-2017-18431
Last Modified: 21 Nov 2024cPanel before 66.0.1 does not reliably perform suspend/unsuspend operations on accounts (CPANEL-13941).
CVE-2017-18430
Last Modified: 21 Nov 2024In cPanel before 66.0.2, user and group ownership may be incorrectly set when using reassign_post_terminate_cruft (SEC-294).
CVE-2017-18429
Last Modified: 21 Nov 2024In cPanel before 66.0.2, Apache HTTP Server SSL domain logs can persist on disk after an account termination (SEC-291).
CVE-2019-9141
Last Modified: 21 Nov 2024ZInsVX.dll ActiveX Control 2018.02 and earlier in Zoneplayer contains a vulnerability that could allow remote attackers to execute arbitrary files by setting the arguments to the ActiveX method. This can be leveraged for remote code execution.
CVE-2017-18428
Last Modified: 21 Nov 2024In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
CVE-2017-18427
Last Modified: 21 Nov 2024In cPanel before 66.0.2, weak log-file permissions can occur after account modification (SEC-289).
CVE-2017-18426
Last Modified: 21 Nov 2024cPanel before 66.0.2 allows resellers to read other accounts' domain log files (SEC-288).
CVE-2017-18425
Last Modified: 21 Nov 2024In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).
CVE-2017-18424
Last Modified: 21 Nov 2024In cPanel before 66.0.2, the Apache HTTP Server configuration file is changed to world-readable when rebuilt (SEC-274).
CVE-2017-18423
Last Modified: 21 Nov 2024In cPanel before 66.0.2, domain log files become readable after log processing (SEC-273).
CVE-2017-18422
Last Modified: 21 Nov 2024In cPanel before 66.0.2, EasyApache 4 conversion sets weak domlog ownership and permissions (SEC-272).
CVE-2017-18421
Last Modified: 21 Nov 2024cPanel before 66.0.2 allows demo accounts to create databases and users (SEC-271).
CVE-2017-18420
Last Modified: 21 Nov 2024cPanel before 66.0.2 allows stored XSS during WHM cPAddons processing (SEC-269).
CVE-2017-18419
Last Modified: 21 Nov 2024cPanel before 66.0.2 allows stored XSS during WHM cPAddons uninstallation (SEC-266).
CVE-2017-18418
Last Modified: 21 Nov 2024cPanel before 66.0.2 allows stored XSS during WHM cPAddons file operations (SEC-265).
CVE-2017-18417
Last Modified: 21 Nov 2024cPanel before 66.0.2 allows stored XSS during WHM cPAddons installation (SEC-263).
CVE-2019-5501
Last Modified: 21 Nov 2024Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 may disclose sensitive LDAP account information to unauthenticated remote attackers.
CVE-2019-5493
Last Modified: 21 Nov 2024Data ONTAP operating in 7-Mode versions prior to 8.2.5P3 are susceptible to a vulnerability which discloses information to an unauthenticated attacker. A successful attack requires that multiple non-default options be enabled.
CVE-2019-4275
Last Modified: 21 Nov 2024IBM Jazz for Service Management 1.1.3, 1.1.3.1, and 1.1.3.2 could allow an unauthorized local user to create unique catalog names that could cause a denial of service. IBM X-Force ID: 160296.
CVE-2018-1987
Last Modified: 21 Nov 2024IBM Spectrum Protect for Enterprise Resource Planning 7.1 and 8.1, if tracing is activated, the IBM Spectrum Protect node password may be displayed in plain text in the ERP trace file. IBM X-Force ID: 154280.
