CVE-2018-20865
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
Source: CVE-2018-20865
CVE-2018-20865
cPanel before 76.0.8 has Self XSS in the WHM Additional Backup Destination field (SEC-459).
Source: CVE-2018-20865
CVE-2018-20863
cPanel before 76.0.8 allows remote attackers to execute arbitrary code via mailing-list attachments (SEC-452).
Source: CVE-2018-20863
CVE-2018-20868
cPanel before 76.0.8 has Stored XSS in the WHM MultiPHP Manager interface (SEC-464).
Source: CVE-2018-20868
CVE-2019-14392
cPanel before 80.0.22 allows remote code execution by a demo account because of incorrect URI dispatching (SEC-501).
Source: CVE-2019-14392
CVE-2019-4456
IBM Daeja ViewONE Professional, Standard & Virtual 5.0.5 and 5.0.6 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 163620.
Source: CVE-2019-4456
CVE-2019-4062
IBM i2 Intelligent Analyis Platform 9.0.0 through 9.1.1 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 157007.
Source: CVE-2019-4062
CVE-2019-4285
IBM WebSphere Application Server – Liberty Admin Center could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could send a specially-crafted HTTP request to hijack the victim’s click actions or launch other client-side browser attacks. IBM X-Force ID: 160513.
Source: CVE-2019-4285
CVE-2018-20867
cPanel before 76.0.8 has an open redirect when resetting connections (SEC-462).
Source: CVE-2018-20867
CVE-2019-11775
All builds of Eclipse OpenJ9 prior to 0.15 contain a bug where the loop versioner may fail to privatize a value that is pulled out of the loop by versioning – for example if there is a condition that is moved out of the loop that reads a field we may not privatize the value of that field in the modified copy of the loop allowing the test to see one value of the field and subsequently the loop to see a modified field value without retesting the condition moved out of the loop. This can lead to a variety of different issues but read out of array bounds is one major consequence of these problems.
Source: CVE-2019-11775
CVE-2019-14390
cPanel before 82.0.2 has stored XSS in the WHM Modify Account interface (SEC-512).
Source: CVE-2019-14390