Vulnerabilities > CVE-2006-3147 - Unspecified vulnerability in Hosting Controller Hosting Controller
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resellers, or change resellers' passwords via unspecified vectors. NOTE: due to the lack of precise details, it is not clear whether this is related to a previously disclosed issue such as CVE-2005-1788.
Vulnerable Configurations
Exploit-Db
description | Hosting Controller <= 6.1 Hotfix 3.1 Privilege Escalation Vulnerability. CVE-2006-3147. Webapps exploit for asp platform |
id | EDB-ID:1987 |
last seen | 2016-01-31 |
modified | 2006-07-06 |
published | 2006-07-06 |
reporter | Soroush Dalili |
source | https://www.exploit-db.com/download/1987/ |
title | Hosting Controller <= 6.1 Hotfix 3.1 - Privilege Escalation Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | HOSTING_CONTROLLER_61_31.NASL |
description | According to its version number, the installation of Hosting Controller on the remote host enables any authenticated user to gain host admin privileges and view all his resellers and change their passwords. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21736 |
published | 2006-06-21 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21736 |
title | Hosting Controller <= 6.1 Hotfix 3.1 Authenticated User Privilege Escalation |
code |
|
References
- http://hostingcontroller.com/english/logs/hotfixlogv61_3_2.html
- http://hostingcontroller.com/english/logs/hotfixlogv61_3_2.html
- http://secunia.com/advisories/20743
- http://secunia.com/advisories/20743
- http://securitytracker.com/id?1016444
- http://securitytracker.com/id?1016444
- http://www.osvdb.org/26693
- http://www.osvdb.org/26693
- http://www.securityfocus.com/bid/18565
- http://www.securityfocus.com/bid/18565
- http://www.vupen.com/english/advisories/2006/2459
- http://www.vupen.com/english/advisories/2006/2459
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27340
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27340