CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.
cPanel before 74.0.8 allows demo accounts to execute arbitrary code via the Fileman::viewfile API (SEC-444).
cPanel before 74.0.8 allows stored XSS in WHM "File and Directory Restoration" interface (SEC-441).
cPanel before 74.0.8 allows self XSS in WHM Style Upload interface (SEC-437).
cPanel before 74.0.8 allows self XSS in the Site Software Moderation interface (SEC-434).
cPanel before 74.0.8 allows self XSS in the WHM Security Questions interface (SEC-433).
cPanel before 74.0.8 allows self XSS in the WHM "Create a New Account" interface (SEC-428).
cPanel before 74.0.8 allows local users to disable the ClamAV daemon (SEC-409).
DrayTek routers before 2018-05-23 allow CSRF attacks to change DNS or DHCP settings, a related issue to CVE-2017-11649.
In Univa Grid Engine before 8.6.3, when configured for Docker jobs and execd spooling on root_squash, weak file permissions ("other" write access) occur in certain cases (GE-6890).
