CVE-2016-10794: Infoleak
Published Aug 6, 2019
·Updated
cPanel before 59.9999.145 allows arbitrary file-read operations because of a multipart form processing error (SEC-154).
Affected Software
5 affected components
Cpanel Cpanel>=11.51.9999.98<11.52.6.6
Cpanel Cpanel>=11.54.0.0<11.54.0.29
Cpanel Cpanel>=55.9999.61<56.0.34
Cpanel Cpanel>=57.9999.48<58.0.29
Cpanel Cpanel>=59.9999.58<59.9999.145
Event History
Aug 6, 2019
CVE Published
via MITRE·01:05 PM
Data Sourced
via MITRE·01:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10794?
The severity of CVE-2016-10794 is classified as a medium risk due to its potential for arbitrary file-read operations.
2
How do I fix CVE-2016-10794?
To fix CVE-2016-10794, upgrade your cPanel installation to version 59.9999.145 or later.
3
What versions of cPanel are affected by CVE-2016-10794?
CVE-2016-10794 affects cPanel versions before 59.9999.145, including various earlier versions.
4
What type of vulnerability is CVE-2016-10794?
CVE-2016-10794 is a security vulnerability related to multipart form processing errors.
5
How can CVE-2016-10794 impact my system?
CVE-2016-10794 can allow attackers to perform unauthorized file-read operations, potentially exposing sensitive information.