CVE-2016-10789: Input Validation
Published Aug 6, 2019
·Updated
cPanel before 60.0.25 allows code execution via the cpsrvd 403 error response handler (SEC-191).
Affected Software
4 affected components
Cpanel Cpanel>=11.54.0.0<11.54.0.33
Cpanel Cpanel>=55.9999.61<56.0.39
Cpanel Cpanel>=57.9999.48<58.0.37
Cpanel Cpanel>=59.9999.58<60.0.25
Event History
Aug 6, 2019
CVE Published
via MITRE·12:59 PM
Data Sourced
via MITRE·12:59 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10789?
CVE-2016-10789 has a high severity level due to the potential for remote code execution.
2
How do I fix CVE-2016-10789?
To fix CVE-2016-10789, update your cPanel to version 60.0.25 or later.
3
Which versions of cPanel are affected by CVE-2016-10789?
CVE-2016-10789 affects cPanel versions before 60.0.25, specifically versions in the 55.x, 56.x, 57.x, 58.x, and 59.x ranges.
4
Can CVE-2016-10789 allow unauthorized access to my server?
Yes, CVE-2016-10789 can allow unauthorized access by enabling code execution through error handling.
5
Is there a workaround for CVE-2016-10789 if I cannot update immediately?
There are no specific workarounds for CVE-2016-10789; it is recommended to upgrade to a secure version as soon as possible.