Vulnerabilities > Hosting Controller

DATE CVE VULNERABILITY TITLE RISK
2005-09-22 CVE-2005-3038 Information Disclosure vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.3
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."
network
low complexity
hosting-controller
5.0
2005-07-12 CVE-2005-2219 Cross-Site Request Forgery vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.1
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.
local
low complexity
hosting-controller
4.6
2005-06-29 CVE-2005-2077 Cross-Site Scripting vulnerability in Hosting Controller Error.ASP
Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.
4.3
2005-06-01 CVE-2005-1788 Unspecified vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.0
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.
network
low complexity
hosting-controller
7.5
2005-05-27 CVE-2005-1784 Remote Security vulnerability in Hosting Controller 6.1.0 Hotfix 3.2
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.
network
low complexity
hosting-controller
7.5
2005-03-07 CVE-2005-0695 Remote Security vulnerability in Hosting Controller
The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field.
network
low complexity
hosting-controller
5.0
2005-03-07 CVE-2005-0694 Information Disclosure vulnerability in Hosting Controller
Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.
network
low complexity
hosting-controller
5.0
2005-01-10 CVE-2004-1217 Unspecified vulnerability in Hosting Controller Hosting Controller 6.1/6.1Hotfix1.4
Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.
network
low complexity
hosting-controller
5.0
2002-08-12 CVE-2002-0776 Unspecified vulnerability in Hosting Controller Hosting Controller 2002
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.
network
low complexity
hosting-controller
7.5
2002-08-12 CVE-2002-0775 Remote Security vulnerability in Hosting Controller
browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.
network
low complexity
hosting-controller
5.0