Vulnerabilities > CVE-2005-0694 - Information Disclosure vulnerability in Hosting Controller

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
hosting-controller
nessus

Summary

Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.

Nessus

NASL familyCGI abuses
NASL idHOSTINGCONTROLLER_INFO_EXPOSURE.NASL
descriptionThe remote host is running Hosting Controller a web hosting management application. The remote version of this software is vulnerable to an information disclosure flaw which may allow an attacker to gather additional data on the remote host. An attacker may download the file
last seen2020-06-01
modified2020-06-02
plugin id17308
published2005-03-10
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/17308
titleHosting Controller HCDiskQuoteService.csv Direct Request Information Disclosure