Skip to content
Noroxi

hosting controller records

37 published records for vendor hosting controller.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
4
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

37 records
  • Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with

    CriticalCVSS 10.0Proof of conceptEPSS 12%

    hosting controller · hosting controllerDec 20, 2007

  • imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp

    CriticalCVSS 10.0Proof of conceptEPSS 4%

    hosting controller · hosting controllerAug 12, 2002

  • Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arb

    CriticalCVSS 10.0No exploitEPSS 4%

    hosting controller · hosting controllerAug 12, 2002

  • Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the

    CriticalCVSS 10.0No exploitEPSS 3%

    hosting controller · hosting controllerAug 12, 2002

  • CVE-2005-1784
    32Monitor

    Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress par

    HighCVSS 7.5Proof of conceptEPSS 6%

    hosting controller · hosting controllerMay 27, 2005

  • CVE-2006-5629
    31Monitor

    Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5Proof of conceptEPSS 3%

    hosting controller · hosting controllerOct 31, 2006

  • CVE-2007-6497
    31Monitor

    Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addres

    HighCVSS 7.5Proof of conceptEPSS 3%

    hosting controller · hosting controllerDec 20, 2007

  • CVE-2005-1788
    31Monitor

    SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL c

    HighCVSS 7.5Proof of conceptEPSS 2%

    hosting controller · hosting controllerJun 1, 2005

  • CVE-2006-1229
    31Monitor

    SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands v

    HighCVSS 7.5No exploitEPSS 2%

    hosting controller · hosting controllerMar 14, 2006

  • CVE-2006-5630
    31Monitor

    Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified For

    HighCVSS 7.5No exploitEPSS 2%

    hosting controller · hosting controllerOct 31, 2006

  • CVE-2002-0776
    31Monitor

    getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifyi

    HighCVSS 7.5No exploitEPSS 2%

    hosting controller · hosting controllerAug 12, 2002

  • CVE-2006-1764
    31Monitor

    Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers

    HighCVSS 7.8No exploitEPSS 2%

    hosting controller · hosting controllerApr 12, 2006

  • CVE-2002-0212
    30Monitor

    The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows r

    HighCVSS 7.5No exploitEPSS 2%

    hosting controller · hosting controllerMay 16, 2002

  • CVE-2007-6498
    30Monitor

    Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitra

    HighCVSS 7.5Proof of conceptEPSS 1%

    hosting controller · hosting controllerDec 20, 2007

  • CVE-2002-0772
    28Monitor

    Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories v

    MediumCVSS 6.4Proof of conceptEPSS 9%

    hosting controller · hosting controllerAug 12, 2002

  • CVE-2007-6496
    28Monitor

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp w

    MediumCVSS 6.8Proof of conceptEPSS 3%

    hosting controller · hosting controllerDec 20, 2007

  • CVE-2007-6495
    27Monitor

    inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories

    MediumCVSS 6.5Proof of conceptEPSS 4%

    hosting controller · hosting controllerDec 20, 2007

  • CVE-2006-3147
    27Monitor

    Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privile

    MediumCVSS 6.5Proof of conceptEPSS 3%

    hosting controller · hosting controllerJun 22, 2006

  • CVE-2006-0581
    27Monitor

    SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the

    MediumCVSS 6.5No exploitEPSS 2%

    hosting controller · hosting controllerFeb 7, 2006

  • CVE-2002-0464
    26Monitor

    Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and dir

    MediumCVSS 6.4No exploitEPSS 2%

    hosting controller · hosting controllerAug 12, 2002

  • CVE-2006-6814
    26Monitor

    Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and

    MediumCVSS 6.3Proof of conceptEPSS 2%

    hosting controller · hosting controllerDec 29, 2006

  • CVE-2007-6502
    23Monitor

    Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and A

    MediumCVSS 5.5Proof of conceptEPSS 3%

    hosting controller · hosting controllerDec 20, 2007

  • CVE-2007-6499
    23Monitor

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage ext

    MediumCVSS 5.5Proof of conceptEPSS 3%

    hosting controller · hosting controllerDec 20, 2007

  • CVE-2007-6501
    23Monitor

    Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type

    MediumCVSS 5.5Proof of conceptEPSS 2%

    hosting controller · hosting controllerDec 20, 2007

  • CVE-2007-6503
    23Monitor

    Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arb

    MediumCVSS 5.5Proof of conceptEPSS 2%

    hosting controller · hosting controllerDec 20, 2007