Vulnerabilities > CVE-2002-0465 - Unspecified vulnerability in Hosting Controller Hosting Controller 1.4/1.4.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
References
- http://archives.neohapsis.com/archives/bugtraq/2002-01/0039.html
- http://archives.neohapsis.com/archives/bugtraq/2002-01/0039.html
- http://www.hostingcontroller.com/english/patches/ForAll/download/foldersecurity.zip
- http://www.hostingcontroller.com/english/patches/ForAll/download/foldersecurity.zip
- http://www.securityfocus.com/bid/3811
- http://www.securityfocus.com/bid/3811
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7824
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7824