CVE-2016-10805: Input Validation
Published Aug 7, 2019
·Updated
cPanel before 57.9999.54 allows demo accounts to execute arbitrary code via ajaxmaketextsyntaxutil.pl (SEC-109).
Affected Software
5 affected components
Cpanel Cpanel>=11.50.0.4<11.50.6.2
Cpanel Cpanel>=11.51.9999.98<11.52.6.1
Cpanel Cpanel>=11.54.0.0<11.54.0.24
Cpanel Cpanel>=55.9999.61<56.0.15
Cpanel Cpanel>=57.9999.48<57.9999.54
Event History
Aug 7, 2019
CVE Published
via MITRE·12:27 PM
Data Sourced
via MITRE·12:27 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10805?
CVE-2016-10805 has a critical severity due to the allowance of arbitrary code execution by demo accounts.
2
How do I fix CVE-2016-10805?
To fix CVE-2016-10805, upgrade your cPanel installation to version 57.9999.54 or later.
3
Which versions of cPanel are affected by CVE-2016-10805?
CVE-2016-10805 affects cPanel versions below 57.9999.54, including versions 11.50.6.2 to 11.50.0.4, 11.51.9999.98 to 11.52.6.1, 11.54.0.0 to 11.54.0.24, and 55.9999.61 to 56.0.15.
4
Can demo accounts in cPanel exploit CVE-2016-10805?
Yes, demo accounts in cPanel can exploit the vulnerability identified as CVE-2016-10805 to execute arbitrary code.
5
What components of cPanel are involved in CVE-2016-10805?
CVE-2016-10805 involves the ajax_maketext_syntax_util.pl component of cPanel, enabling the code execution issue.