Vulnerabilities > Hosting Controller > Medium

DATE CVE VULNERABILITY TITLE RISK
2006-04-05 CVE-2006-1621 Directory Traversal vulnerability in Hosting Controller Hosting Controller 2002Rc1
Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary files via an absolute path in the OpenPath parameter.
network
low complexity
hosting-controller
4.0
2006-04-05 CVE-2006-1620 Remote vulnerability in Hosting Controller Hosting Controller 2002Rc1
admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE.
network
low complexity
hosting-controller
5.0
2006-02-08 CVE-2006-0581 SQL-Injection vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.8
SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP parameter in IPManager.asp.
network
low complexity
hosting-controller
6.5
2005-09-22 CVE-2005-3038 Information Disclosure vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.3
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."
network
low complexity
hosting-controller
5.0
2005-07-12 CVE-2005-2219 Cross-Site Request Forgery vulnerability in Hosting Controller Hosting Controller 6.1Hotfix2.1
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.
local
low complexity
hosting-controller
4.6
2005-06-29 CVE-2005-2077 Cross-Site Scripting vulnerability in Hosting Controller Error.ASP
Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.
4.3
2005-03-07 CVE-2005-0695 Remote Security vulnerability in Hosting Controller
The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field.
network
low complexity
hosting-controller
5.0
2005-03-07 CVE-2005-0694 Information Disclosure vulnerability in Hosting Controller
Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via a direct request to HCDiskQuotaService.csv.
network
low complexity
hosting-controller
5.0
2005-01-10 CVE-2004-1217 Unspecified vulnerability in Hosting Controller Hosting Controller 6.1/6.1Hotfix1.4
Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.
network
low complexity
hosting-controller
5.0
2002-08-12 CVE-2002-0775 Remote Security vulnerability in Hosting Controller
browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.
network
low complexity
hosting-controller
5.0