NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 81032 | CVE-2002-2081 | cphost.dll in Microsoft Site Server 3.0 allows remote attackers to cause a denial of service (disk consumption) via an HTTP POST of a file with a long TargetURL parameter, which causes Site Server to abort and leaves the uploaded file in c: emp. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
| 49430 | CVE-2009-2168 | cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit when the supplied credentials are incorrect, which allows remote attackers to bypass authentication by providing arbitrary username and password parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-06-23 | View | |
| 70926 | CVE-2004-0490 | cPanel, when compiling Apache 1.3.29 and PHP with the mod_phpsuexec option, does not set the --enable-discard-path option, which causes php to use the SCRIPT_FILENAME variable to find and execute a script instead of the PATH_TRANSLATED variable, which allows local users to execute arbitrary PHP code as other users via a URL that references the attacker's script after the user's script, which executes the attacker's script with the user's privileges, a different vulnerability than CVE-2004-0529. | 2 | 7.2 | High | 2017-07-18 | 2017-07-10 | View | |
| 61510 | CVE-2006-2825 | cPanel does not automatically synchronize the PHP open_basedir configuration directive between the main server and virtual hosts that share physical directories, which might allow a local user to bypass open_basedir restrictions and access other virtual hosts via a PHP script that uses a main server URL (such as ~username) that is blocked by the user"s own open_basedir directive, but not the main server"s open_basedir directive. | 2 | 5.1 | Medium | 2016-12-20 | 2008-11-15 | View | |
| 71983 | CVE-2004-1604 | cPanel 9.9.1-RELEASE-3 allows remote authenticated users to chmod arbitrary files via a symlink attack on the _private directory, which is created when Front Page extensions are enabled. | 2 | 5 | Medium | 2016-12-20 | 2016-10-17 | View |
Page 14985 of 17672, showing 5 records out of 88360 total, starting on record 74921, ending on 74925