Vulnerabilities
Vulnerable Software
Cpanel:  >> Cpanel  >> 59.9999.145  Security Vulnerabilities
cPanel before 64.0.21 allows certain file-chmod operations via /scripts/convert_roundcube_mysql2sqlite (SEC-255).
CVSS Score
4.5
EPSS Score
0.0
Published
2019-08-02
cPanel before 64.0.21 allows code execution via Rails configuration files (SEC-259).
CVSS Score
6.7
EPSS Score
0.001
Published
2019-08-02
cPanel before 62.0.24 allows stored XSS in the WHM cPAddons install interface (SEC-262).
CVSS Score
5.4
EPSS Score
0.003
Published
2019-08-02
In cPanel before 62.0.17, addon domain conversion did not require a package for resellers (SEC-208).
CVSS Score
2.7
EPSS Score
0.004
Published
2019-08-02
cPanel before 62.0.17 allows self XSS in the WHM cPAddons showsecurity interface (SEC-217).
CVSS Score
6.1
EPSS Score
0.004
Published
2019-08-02
cPanel before 62.0.17 allows arbitrary file-read operations via WHM /styled/ URLs (SEC-218).
CVSS Score
4.4
EPSS Score
0.001
Published
2019-08-02
cPanel before 62.0.17 allows file overwrite when renaming an account (SEC-219).
CVSS Score
3.3
EPSS Score
0.001
Published
2019-08-02
cPanel before 62.0.17 allows arbitrary code execution during account modification (SEC-220).
CVSS Score
7.8
EPSS Score
0.001
Published
2019-08-02
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
CVSS Score
3.5
EPSS Score
0.001
Published
2019-08-02
cPanel before 64.0.21 allows a Webmail account to execute code via forwarders (SEC-240).
CVSS Score
4.4
EPSS Score
0.001
Published
2019-08-02


Contact Us

Shodan ® - All rights reserved