CVE-2017-18440: Input Validation
Published Aug 2, 2019
·Updated
cPanel before 64.0.21 allows demo users to execute traceroute via api2 (SEC-244).
Affected Software
5 affected components
Cpanel Cpanel>=56.0.1<56.0.49
Cpanel Cpanel>=58.0.3<58.0.49
Cpanel Cpanel>=60.0.3<60.0.43
Cpanel Cpanel>=62.0.1<62.0.24
Cpanel Cpanel>=64.0.0<64.0.21
Event History
Aug 2, 2019
CVE Published
via MITRE·04:16 PM
Data Sourced
via MITRE·04:16 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-18440?
CVE-2017-18440 has a medium severity level due to the unauthorized access executable by demo users.
2
How do I fix CVE-2017-18440?
To fix CVE-2017-18440, you should upgrade cPanel to version 64.0.21 or later.
3
What software is affected by CVE-2017-18440?
CVE-2017-18440 affects cPanel versions prior to 64.0.21.
4
Who can exploit CVE-2017-18440?
Demo users are able to exploit CVE-2017-18440 to execute traceroute via api2.
5
What does CVE-2017-18440 allow attackers to do?
CVE-2017-18440 allows unauthorized demo users to execute traceroute commands.