Description
cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416).
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-13423 | cPanel before 74.0.0 allows Apache HTTP Server configuration injection because of DocumentRoot variable interpolation (SEC-416). |
References
| Link | Providers |
|---|---|
| https://documentation.cpanel.net/display/CL/74+Change+Log |
|
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T12:12:29.714Z
Reserved: 2019-07-31T00:00:00.000Z
Link: CVE-2018-20885
No data.
Status : Modified
Published: 2019-08-01T13:15:13.147
Modified: 2024-11-21T04:02:23.567
Link: CVE-2018-20885
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD