Vulnerabilities > CVE-2002-0776 - Unspecified vulnerability in Hosting Controller Hosting Controller 2002
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://hostingcontroller.com/english/logs/sp2log.html
- http://hostingcontroller.com/english/logs/sp2log.html
- http://online.securityfocus.com/archive/1/282129
- http://online.securityfocus.com/archive/1/282129
- http://www.iss.net/security_center/static/9554.php
- http://www.iss.net/security_center/static/9554.php
- http://www.securityfocus.com/bid/5229
- http://www.securityfocus.com/bid/5229