Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
cpanel cpanel vulnerabilities and exploits
(subscribe to this query)
1000
VMScore
CVE-2015-2844
The cpanel function in go_site.php in GoAutoDial GoAdmin CE prior to 3.3-1420434000 allows remote malicious users to execute arbitrary commands via the $action portion of the PATH_INFO.
Goautodial Goadmin Ce 3.0
Goautodial Goadmin Ce 3.3
1 EDB exploit
3 Github repositories
1000
VMScore
CVE-2015-2845
The cpanel function in go_site.php in GoAutoDial GoAdmin CE prior to 3.3-1421902800 allows remote malicious users to execute arbitrary commands via the $type portion of the PATH_INFO.
Goautodial Goadmin Ce 3.3
Goautodial Goadmin Ce 3.0
2 EDB exploits
3 Github repositories
1000
VMScore
CVE-2004-1769
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and previous versions, including 8.x, allows remote malicious users to execute arbitrary code via the user parameter to resetpass.
Cpanel Cpanel 6.4
Cpanel Cpanel 6.4.1
Cpanel Cpanel 5.0
Cpanel Cpanel 5.3
Cpanel Cpanel 7.0
Cpanel Cpanel 8.0
Cpanel Cpanel 9.0
Cpanel Cpanel 6.4.2
Cpanel Cpanel 6.4.2 Stable 48
Cpanel Cpanel 6.0
Cpanel Cpanel 6.2
Cpanel Cpanel 9.1
1 EDB exploit
1 Github repository
1000
VMScore
CVE-2004-1770
The login page for cPanel 9.1.0, and possibly other versions, allows remote malicious users to execute arbitrary code via shell metacharacters in the user parameter.
Cpanel Cpanel 5.0
Cpanel Cpanel 5.3
Cpanel Cpanel 7.0
Cpanel Cpanel 8.0
Cpanel Cpanel 6.4
Cpanel Cpanel 6.4.1
Cpanel Cpanel 6.0
Cpanel Cpanel 6.2
Cpanel Cpanel 9.0
Cpanel Cpanel 9.1
Cpanel Cpanel 6.4.2
Cpanel Cpanel 6.4.2 Stable 48
1 EDB exploit
1000
VMScore
CVE-2003-1425
guestbook.cgi in cPanel 5.0 allows remote malicious users to execute arbitrary commands via the template parameter.
Cpanel Cpanel 5.0
4 EDB exploits
935
VMScore
CVE-2004-1875
Multiple cross-site scripting (XSS) vulnerabilities in cPanel 9.1.0-R85 allow remote malicious users to inject arbitrary web script or HTML via the (1) email parameter to testfile.html, (2) file parameter to erredit.html, (3) dns parameter to dnslook.html, (4) account parameter t...
Cpanel Cpanel 9.1.0 R85
1 EDB exploit
905
VMScore
CVE-2007-1455
Multiple absolute path traversal vulnerabilities in Fantastico, as used with cPanel 10.x, allow remote authenticated users to include and execute arbitrary local files via (1) the userlanguage parameter to includes/load_language.php or (2) the fantasticopath parameter to includes...
Cpanel-host Fantastico De Luxe
1 EDB exploit
905
VMScore
CVE-2006-5014
Unspecified vulnerability in cPanel prior to 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.
Cpanel Cpanel 10.8.2 118
Cpanel Cpanel 5.0
Cpanel Cpanel 5.3
Cpanel Cpanel 6.0
Cpanel Cpanel 10.2.0 R82
Cpanel Cpanel 10.8.1 113
Cpanel Cpanel 6.2
Cpanel Cpanel 6.4.1
Cpanel Cpanel 9.1.0 R85
Cpanel Cpanel 9.9.1 R3
Cpanel Cpanel 6.4.2 Stable 48
Cpanel Cpanel 7.0
Cpanel Cpanel 8.0
Cpanel Cpanel 9.0
Cpanel Cpanel 9.1
Cpanel Cpanel 10.6.0 R137
Cpanel Cpanel 6.4
Cpanel Cpanel 6.4.2
Cpanel Cpanel 9.4.1 R64
1 EDB exploit
890
VMScore
CVE-2016-10817
cPanel prior to 57.9999.54 allows SQL Injection via the ModSecurity TailWatch log file (SEC-123).
Cpanel Cpanel
890
VMScore
CVE-2016-10855
cPanel prior to 11.54.0.4 allows unauthenticated arbitrary code execution via cpsrvd (SEC-91).
Cpanel Cpanel
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4671
unauthorized
CVE-2024-4776
CVE-2024-3407
CVE-2024-26026
CVE-2024-32888
wireless
CVE-2024-4656
template injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »