5
CVE-2006-1620
- EPSS 2.19%
- Veröffentlicht 05.04.2006 10:04:00
- Zuletzt bearbeitet 16.06.2026 22:23:18
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hosting Controller ≫ Hosting Controller Version <= 6.1_hotfix_3.3
Hosting Controller ≫ Hosting Controller Version2002_rc_1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.19% | 0.801 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
http://hostingcontroller.com/english/logs/Post-Hotfix-3_3-sec-Patch-ReleaseNotes.html
http://secunia.com/advisories/28973
http://www.osvdb.org/24773
http://www.securityfocus.com/archive/1/429731/100/0/threaded
http://www.securityfocus.com/archive/1/485028/100/0/threaded
http://www.securityfocus.com/bid/26862
https://exchange.xforce.ibmcloud.com/vulnerabilities/25673
https://exchange.xforce.ibmcloud.com/vulnerabilities/39038
https://www.exploit-db.com/exploits/4730