Skip to main content

Vendor/product archive

ehcp / easy_hosting_control_panel CVEs

Beta · best-effort

12 CVEs tagged to ehcp / easy_hosting_control_panel0 Critical, 4 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2025-50859

Published Aug 22, 2025

Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via th…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50858

Published Aug 22, 2025

Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript v…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50860

Published Aug 21, 2025

SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananala…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50926

Published Aug 19, 2025

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50928

Published Aug 8, 2025

Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function.

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-50927

Published Aug 8, 2025

A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via inject…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-6619

Published May 11, 2018

Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt.

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6617

Published May 11, 2018

Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for th…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6458

Published May 11, 2018

Easy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-6362

Published May 11, 2018

Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1