CVE-2017-18425

Severity CVSS v4.0:
Pending analysis
Type:
CWE-275 Permission Issues
Publication date:
02/08/2019
Last modified:
09/08/2019

Description

In cPanel before 66.0.2, the cpdavd_error_log file can be created with weak permissions (SEC-280).

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 56.0.1 (including) 56.0.51 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 58.0.3 (including) 58.0.52 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 60.0.3 (including) 60.0.45 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 62.0.1 (including) 62.0.27 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 64.0.0 (including) 64.0.33 (excluding)
cpe:2.3:a:cpanel:cpanel:*:*:*:*:*:*:*:* 66.0.1 (including) 66.0.2 (excluding)