Hosting Controller

Hosting Controller

37 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 1.43%
  • Veröffentlicht 20.12.2007 20:46:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary plan via a request to hosting/importhostingplans.asp; or (2) change an arbitrary plan via a request to ...

Exploit
  • EPSS 0.65%
  • Veröffentlicht 29.12.2006 11:28:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backslash) sequences in the BrowsePat...

Exploit
  • EPSS 1.53%
  • Veröffentlicht 31.10.2006 22:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified ForumID parameter in a disableforum action in DisableForum.asp and (2) create an arbitrary forum virtual director...

Exploit
  • EPSS 1.5%
  • Veröffentlicht 31.10.2006 22:07:00
  • Zuletzt bearbeitet 09.04.2025 00:30:58

Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that t...

  • EPSS 1.64%
  • Veröffentlicht 22.06.2006 22:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resellers, or change resellers' passwords via unspecified vectors. NOTE: due to the lack of pre...

  • EPSS 0.37%
  • Veröffentlicht 13.04.2006 01:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials. NOTE: the provenance of this inf...

  • EPSS 0.42%
  • Veröffentlicht 05.04.2006 10:04:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary files via an absolute path in the OpenPath parameter.

  • EPSS 1.14%
  • Veröffentlicht 05.04.2006 10:04:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was...

  • EPSS 1.04%
  • Veröffentlicht 14.03.2006 19:06:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely...

Exploit
  • EPSS 1.24%
  • Veröffentlicht 08.02.2006 01:02:00
  • Zuletzt bearbeitet 03.04.2025 01:03:51

SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp.