Cpanel

Cpanel

419 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.32%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:40:16

cPanel before 11.52.0.13 does not prevent arbitrary file-read operations via get_information_for_applications (CPANEL-1221).

  • EPSS 2.06%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:44:54

cPanel before 11.54.0.4 allows arbitrary code execution via scripts/synccpaddonswithsqlhost (SEC-83).

  • EPSS 0.64%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:44:54

cPanel before 11.54.0.4 allows self XSS in the WHM PHP Configuration editor interface (SEC-84).

  • EPSS 0.96%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:44:54

cPanel before 11.54.0.4 lacks ACL enforcement in the AppConfig subsystem (SEC-85).

  • EPSS 0.64%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:44:54

cPanel before 11.54.0.4 allows stored XSS in the WHM Feature Manager interface (SEC-86).

  • EPSS 0.64%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:44:54

cPanel before 11.54.0.4 allows self XSS in the X3 Entropy Banner interface (SEC-87).

  • EPSS 2.58%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:44:54

cPanel before 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).

  • EPSS 0.96%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:44:55

cPanel before 11.54.0.0 allows subaccounts to discover sensitive data through comet feeds (SEC-29).

  • EPSS 1.02%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:44:55

cPanel before 11.54.0.0 allows a bypass of the e-mail sending limit (SEC-60).

  • EPSS 2.5%
  • Veröffentlicht 01.08.2019 15:15:12
  • Zuletzt bearbeitet 21.11.2024 02:44:55

cPanel before 11.54.0.0 allows unauthenticated arbitrary code execution via DNS NS entry poisoning (SEC-64).