10

CVE-2007-6494

Exploit
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction and ChangeSkin parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hosting ControllerHosting Controller Version6.1_hotfix_3.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 11.77% 0.955
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

http://www.securityfocus.com/archive/1/485028/100/0/threaded
http://www.securityfocus.com/bid/26862
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/39038
https://www.exploit-db.com/exploits/4730
http://osvdb.org/44186
http://securityreason.com/securityalert/3474
http://securitytracker.com/id?1019222