Vulnerabilities (CVE)

Filtered by CWE-200
Total 7102 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-10790 1 Cpanel 1 Cpanel 2019-08-12 5.0 MEDIUM 7.5 HIGH
cPanel before 60.0.25 does not use TLS for HTTP POSTs to listinput.cpanel.net (SEC-192).
CVE-2017-18474 1 Cpanel 1 Cpanel 2019-08-12 6.8 MEDIUM 6.5 MEDIUM
cPanel before 62.0.4 allows arbitrary file-read operations via Exim valiases (SEC-201).
CVE-2017-18428 1 Cpanel 1 Cpanel 2019-08-12 1.9 LOW 2.5 LOW
In cPanel before 66.0.2, Apache HTTP Server domlogs become temporarily world-readable during log processing (SEC-290).
CVE-2017-18478 1 Cpanel 1 Cpanel 2019-08-12 4.0 MEDIUM 6.5 MEDIUM
In cPanel before 62.0.4 incorrect ACL checks could occur in xml-api for Rearrange Account actions (SEC-207).
CVE-2018-20943 1 Cpanel 1 Cpanel 2019-08-09 1.9 LOW 2.5 LOW
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon a post-update task (SEC-352).
CVE-2017-18391 1 Cpanel 1 Cpanel 2019-08-09 1.9 LOW 2.5 LOW
cPanel before 68.0.15 allows attackers to read backup files because they are world-readable during a short time interval (SEC-323).
CVE-2016-10786 1 Cpanel 1 Cpanel 2019-08-09 4.0 MEDIUM 6.5 MEDIUM
cPanel before 60.0.25 allows members of the nobody group to read Apache HTTP Server SSL keys (SEC-186).
CVE-2016-10811 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/unsuspendacct exposed TTYs (SEC-116).
CVE-2016-10810 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/maildir_converter exposed a TTY to an unprivileged process (SEC-115).
CVE-2016-10809 1 Cpanel 1 Cpanel 2019-08-09 9.0 HIGH 8.8 HIGH
In cPanel before 57.9999.54, /scripts/checkinfopages exposed a TTY to an unprivileged process (SEC-114).
CVE-2018-20942 1 Cpanel 1 Cpanel 2019-08-09 1.9 LOW 2.5 LOW
cPanel before 68.0.27 allows attackers to read root's crontab file during a short time interval upon configuring crontab (SEC-351).
CVE-2017-18436 1 Cpanel 1 Cpanel 2019-08-09 2.7 LOW 3.5 LOW
cPanel before 64.0.21 allows demo accounts to read files via a Fileman::getfileactions API2 call (SEC-239).
CVE-2016-10785 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 6.5 MEDIUM
cPanel before 60.0.25 allows attackers to discover file contents during file copy operations (SEC-185).
CVE-2018-20952 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 6.5 MEDIUM
cPanel before 68.0.27 creates world-readable files during use of WHM Apache Includes Editor (SEC-388).
CVE-2018-20941 1 Cpanel 1 Cpanel 2019-08-08 4.7 MEDIUM 5.6 MEDIUM
cPanel before 68.0.27 allows arbitrary file-read operations via restore adminbin (SEC-349).
CVE-2016-10844 1 Cpanel 1 Cpanel 2019-08-08 4.0 MEDIUM 6.5 MEDIUM
The chcpass script in cPanel before 11.54.0.4 reveals a password hash (SEC-77).
CVE-2009-3086 1 Rubyonrails 1 Rails 2019-08-08 5.0 MEDIUM N/A
A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.
CVE-2018-20946 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read zone information because a world-readable archive is created by the archive_sync_zones script (SEC-355).
CVE-2018-20944 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows attackers to read a copy of httpd.conf that is created during a syntax test (SEC-353).
CVE-2018-20939 1 Cpanel 1 Cpanel 2019-08-07 2.1 LOW 3.3 LOW
cPanel before 68.0.27 allows a user to discover contents of directories (that are not owned by that user) by leveraging backups (SEC-339).