Vulnerabilities > CVE-2002-0464 - Unspecified vulnerability in Hosting Controller Hosting Controller 1.4/1.4.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories via a .. (dot dot) in arguments to (1) file_editor.asp, (2) folderactions.asp, or (3) editoractions.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://www.hostingcontroller.com/english/patches/ForAll/download/dot-slash.zip
- http://www.hostingcontroller.com/english/patches/ForAll/download/dot-slash.zip
- http://www.securityfocus.com/archive/1/262734
- http://www.securityfocus.com/archive/1/262734
- http://www.securityfocus.com/bid/4311
- http://www.securityfocus.com/bid/4311