CVE-2016-10836
Last Modified: 21 Nov 2024cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
CVE-2018-20935
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows stored XSS in via a WHM "Reset a DNS Zone" action (SEC-412).
CVE-2018-20934
Last Modified: 21 Nov 2024cPanel before 70.0.23 does not prevent e-mail account suspensions from being applied to unowned accounts (SEC-411).
CVE-2018-20933
Last Modified: 21 Nov 2024cPanel before 70.0.23 has Stored XSS via an WHM Edit DNS Zone action (SEC-410).
CVE-2018-20932
Last Modified: 21 Nov 2024cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
CVE-2018-20931
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
CVE-2018-20930
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows .htaccess restrictions bypass when Htaccess Optimization is enabled (SEC-401).
CVE-2016-10837
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
CVE-2016-10838
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).
CVE-2018-20928
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows stored XSS via the cpaddons vendor interface (SEC-391).
CVE-2016-10839
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).
CVE-2016-10840
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
CVE-2016-10841
Last Modified: 21 Nov 2024The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).
CVE-2016-10842
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).
CVE-2016-10843
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
CVE-2016-10844
Last Modified: 21 Nov 2024The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
CVE-2016-10845
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/check_system_storable (SEC-78).
CVE-2016-10846
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows arbitrary file-chown and file-chmod operations during Roundcube database conversions (SEC-79).
CVE-2016-10847
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows arbitrary file-read and file-write operations via scripts/fixmailboxpath (SEC-80).
CVE-2016-10848
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows arbitrary file-overwrite operations in scripts/quotacheck (SEC-81).
CVE-2016-10849
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows certain file-chmod operations in scripts/secureit (SEC-82).
CVE-2019-14486
Last Modified: 21 Nov 2024GnuCOBOL 2.2 has a buffer overflow in cb_evaluate_expr in cobc/field.c via crafted COBOL source code.
CVE-2018-20929
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows an open redirect via the /unprotected/redirect.html endpoint (SEC-392).
CVE-2018-20927
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows jailshell escape because of incorrect crontab parsing (SEC-382).
CVE-2018-20926
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows local privilege escalation via the WHM Locale XML Upload interface (SEC-380).
CVE-2018-20925
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows local privilege escalation via the WHM Legacy Language File Upload interface (SEC-379).
CVE-2018-20924
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows arbitrary file-read and file-unlink operations via WHM style uploads (SEC-378).
CVE-2016-10850
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).
CVE-2018-20923
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows stored XSS via a WHM Synchronize DNS Records action (SEC-377).
CVE-2018-20922
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows stored XSS via a WHM DNS Cleanup action (SEC-376).
CVE-2018-20921
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows stored XSS via a WHM "Delete a DNS Zone" action (SEC-375).
CVE-2018-20920
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-374).
CVE-2018-20919
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows stored XSS via a WHM Create Account action (SEC-373).
CVE-2016-10851
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).
CVE-2018-20918
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows stored XSS in WHM DNS Cluster (SEC-372).
CVE-2016-10852
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).
CVE-2018-20917
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows any user to disable Solr (SEC-371).
CVE-2018-20916
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows Stored XSS via a WHM Edit MX Entry (SEC-370).
CVE-2018-20915
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows stored XSS via a WHM Edit DNS Zone action (SEC-369).
CVE-2016-10853
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).
CVE-2018-20914
Last Modified: 21 Nov 2024In cPanel before 70.0.23, OpenID providers can inject arbitrary data into cPanel session files (SEC-368).
CVE-2019-14259
Last Modified: 21 Nov 2024On the Polycom Obihai Obi1022 VoIP phone with firmware 5.1.11, a command injection (missing input validation) issue in the NTP server IP address field for the "Time Service Settings web" interface allows an authenticated remote attacker in the same network to trigger OS commands via shell commands in a POST request.
CVE-2016-10854
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).
CVE-2018-20913
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows attackers to read the root accesshash via the WHM /cgi/trustclustermaster.cgi (SEC-364).
CVE-2018-20912
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows demo accounts to execute code via awstats (SEC-362).
CVE-2016-10855
Last Modified: 21 Nov 2024cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
CVE-2018-20911
Last Modified: 21 Nov 2024cPanel before 70.0.23 allows code execution because "." is in @INC during a Perl syntax check of cpaddonsup (SEC-359).
CVE-2016-10856
Last Modified: 21 Nov 2024cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).
CVE-2016-10857
Last Modified: 21 Nov 2024cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).
CVE-2016-10858
Last Modified: 21 Nov 2024cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).
