Vulnerabilities > CVE-2002-0466 - Unspecified vulnerability in Hosting Controller Hosting Controller 1.4/1.4.1
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN hosting-controller
nessus
Summary
Hosting Controller 1.4.1 and earlier allows remote attackers to browse arbitrary directories via a full C: style pathname in the filepath arguments to (1) Statsbrowse.asp, (2) servubrowse.asp, (3) browsedisk.asp, (4) browsewebalizerexe.asp, or (5) sqlbrowse.asp.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | CGI abuses |
NASL id | HOSTING_CONTROLLER.NASL |
description | The Hosting Controller application resides on this server. This version is vulnerable to multiple remote exploits. At attacker may make use of this vulnerability and use it to gain access to confidential data and/or escalate their privileges on the Web server. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11745 |
published | 2003-06-17 |
reporter | This script is Copyright (C) 2003-2018 John Lampe |
source | https://www.tenable.com/plugins/nessus/11745 |
title | Hosting Controller Multiple Script Arbitrary Directory Browsing |
code |
|
References
- http://archives.neohapsis.com/archives/bugtraq/2002-01/0039.html
- http://archives.neohapsis.com/archives/bugtraq/2002-01/0039.html
- http://www.hostingcontroller.com/english/patches/ForAll/download/foldersecurity.zip
- http://www.hostingcontroller.com/english/patches/ForAll/download/foldersecurity.zip
- http://www.securityfocus.com/bid/3808
- http://www.securityfocus.com/bid/3808
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7823
- https://exchange.xforce.ibmcloud.com/vulnerabilities/7823