CVE-2017-18406: SQL Injection
Published Aug 2, 2019
·Updated
cPanel before 67.9999.103 allows SQL injection during eximstats processing (SEC-276).
Affected Software
3 affected components
Cpanel Cpanel>=63.9999.74<64.0.40
Cpanel Cpanel>=65.9999.38<66.0.23
Cpanel Cpanel>=67.9999.64<67.9999.103
Event History
Aug 2, 2019
CVE Published
via MITRE·01:45 PM
Data Sourced
via MITRE·01:45 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18406?
CVE-2017-18406 has a high severity due to its potential for SQL injection attacks.
2
How do I fix CVE-2017-18406?
To fix CVE-2017-18406, upgrade to cPanel versions 68 and above to ensure the SQL injection vulnerability is patched.
3
What versions of cPanel are affected by CVE-2017-18406?
CVE-2017-18406 affects cPanel versions before 67.9999.103, including versions 64.0.40 and 66.0.23.
4
What types of attacks can CVE-2017-18406 facilitate?
CVE-2017-18406 can facilitate SQL injection attacks that may lead to unauthorized data access or manipulation.
5
Is there a risk of data exposure with CVE-2017-18406?
Yes, the SQL injection vulnerability in CVE-2017-18406 poses a risk of data exposure if exploited.