Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
easy hosting control panel vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2007-6178
Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and previous versions allow remote malicious users to execute arbitrary PHP code via a URL in the confdir parameter to (1) dbutil.bck.php and (2) dbutil.php in config/.
Easy Hosting Control Panel Easy Hosting Control Panel 0.22.8
1 EDB exploit
2.1
CVSSv2
CVE-2018-6619
Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for malicious users to crack database passwords by leveraging use of a weak hashing algorithm without a salt.
Ehcp Easy Hosting Control Panel 0.37.12.b
4.3
CVSSv2
CVE-2018-6362
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.
Ehcp Easy Hosting Control Panel 0.37.12.b
6.8
CVSSv2
CVE-2018-6458
Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote malicious users to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
Ehcp Easy Hosting Control Panel 0.37.12.b
2.1
CVSSv2
CVE-2018-6617
Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows malicious users to change passwords of arbitrary database users by leveraging failure to ask for the current password.
Ehcp Easy Hosting Control Panel 0.37.12.b
2.1
CVSSv2
CVE-2018-6618
Easy Hosting Control Panel (EHCP) v0.37.12.b allows malicious users to obtain sensitive information by leveraging cleartext password storage.
Ehcp Easy Hosting Control Panel 0.37.12.b
4.3
CVSSv2
CVE-2018-6361
Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.
Ehcp Easy Hosting Control Panel 0.37.12.b
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3400
CVE-2023-7252
CVE-2024-21111
denial of service
CVE-2024-29661
CVE-2024-22856
remote attackers
encryption
CVE-2023-38299
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started