Vulnerabilities > Hosting Controller > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2006-04-05 | CVE-2006-1621 | Directory Traversal vulnerability in Hosting Controller Hosting Controller 2002Rc1 Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary files via an absolute path in the OpenPath parameter. | 4.0 |
2006-04-05 | CVE-2006-1620 | Remote vulnerability in Hosting Controller Hosting Controller 2002Rc1 admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. | 5.0 |
2006-02-08 | CVE-2006-0581 | SQL-Injection vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.8 SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp. | 6.5 |
2005-09-22 | CVE-2005-3038 | Information Disclosure vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.3 Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability." | 5.0 |
2005-07-12 | CVE-2005-2219 | Cross-Site Request Forgery vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.1 Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action. | 4.6 |
2005-06-29 | CVE-2005-2077 | Cross-Site Scripting vulnerability in Hosting Controller Error.ASP Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter. network hosting-controller | 4.3 |
2005-03-07 | CVE-2005-0695 | Remote Security vulnerability in Hosting Controller The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field. | 5.0 |
2005-03-07 | CVE-2005-0694 | Information Disclosure vulnerability in Hosting Controller Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv. | 5.0 |
2005-01-10 | CVE-2004-1217 | Unspecified vulnerability in Hosting Controller Hosting Controller 6.1/6.1Hotfix1.4 Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp. | 5.0 |
2002-08-12 | CVE-2002-0775 | Remote Security vulnerability in Hosting Controller browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter. | 5.0 |