Vulnerabilities > CVE-2006-1620 - Unspecified vulnerability in Hosting Controller Hosting Controller 2002Rc1

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
hosting-controller
exploit available

Summary

admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.

Vulnerable Configurations

Part Description Count
Application
Hosting_Controller
2

Exploit-Db

idEDB-ID:4730