CVE-2016-10807: Input Validation
Published Aug 7, 2019
·Updated
cPanel before 57.9999.54 allows certain denial-of-service outcomes via /scripts/killpvhost (SEC-112).
Affected Software
5 affected components
Cpanel Cpanel>=11.50.0.4<11.50.6.2
Cpanel Cpanel>=11.51.9999.98<11.52.6.1
Cpanel Cpanel>=11.54.0.0<11.54.0.24
Cpanel Cpanel>=55.9999.61<56.0.15
Cpanel Cpanel>=57.9999.48<57.9999.54
Event History
Aug 7, 2019
CVE Published
via MITRE·12:29 PM
Data Sourced
via MITRE·12:29 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10807?
CVE-2016-10807 is classified as a denial-of-service vulnerability affecting specific versions of cPanel.
2
How do I fix CVE-2016-10807?
To fix CVE-2016-10807, upgrade to cPanel version 57.9999.54 or later.
3
What versions of cPanel are affected by CVE-2016-10807?
CVE-2016-10807 affects cPanel versions prior to 57.9999.54 and several specific older versions.
4
Is CVE-2016-10807 exploitable remotely?
Yes, CVE-2016-10807 can be remotely exploited, leading to denial-of-service conditions.
5
What does CVE-2016-10807 impact in cPanel?
CVE-2016-10807 impacts the cPanel functionality related to scripts/killpvhost, allowing certain Denial-of-Service outcomes.