Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In August 2019
cPanel before 70.0.23 exposes Apache HTTP Server logs after creation of certain domains (SEC-406).
CVSS Score
2.7
EPSS Score
0.002
Published
2019-08-01
cPanel before 55.9999.141 allows arbitrary file-read operations during authentication with caldav (SEC-108).
CVSS Score
6.5
EPSS Score
0.003
Published
2019-08-01
cPanel before 11.54.0.4 allows arbitrary code execution because of an unsafe @INC path (SEC-46).
CVSS Score
7.5
EPSS Score
0.01
Published
2019-08-01
cPanel before 11.54.0.4 allows arbitrary file-read operations via the bin/fmq script (SEC-70).
CVSS Score
6.5
EPSS Score
0.002
Published
2019-08-01
cPanel before 11.54.0.4 allows SQL injection in bin/horde_update_usernames (SEC-71).
CVSS Score
8.1
EPSS Score
0.003
Published
2019-08-01
cPanel before 11.54.0.4 allows arbitrary code execution during locale duplication (SEC-72).
CVSS Score
8.8
EPSS Score
0.009
Published
2019-08-01
The bin/mkvhostspasswd script in cPanel before 11.54.0.4 discloses password hashes (SEC-73).
CVSS Score
5.3
EPSS Score
0.003
Published
2019-08-01
cPanel before 11.54.0.4 allows certain file-read operations in bin/setup_global_spam_filter.pl (SEC-74).
CVSS Score
6.5
EPSS Score
0.003
Published
2019-08-01
cPanel before 11.54.0.4 allows code execution in the context of shared users via JSON-API (SEC-76).
CVSS Score
8.1
EPSS Score
0.008
Published
2019-08-01
TestLink 1.9.19 has XSS via the error.php message parameter.
CVSS Score
6.1
EPSS Score
0.002
Published
2019-08-01


Contact Us

Shodan ® - All rights reserved