Записи hosting controller
37 опубликованных записей вендора hosting controller.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 4
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Записи по годам
Столбик: всего · тёмная часть: CISA KEV.
Повторяющиеся классы
- CWE-264 Permissions, Privileges, and Access Controls8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
37 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2007-6494Proof of concept | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with hosting controller · hosting controller · CWE-20 | Критическая10,0 | — | 11,8 % | 20 дек. 2007 г. |
41В плане | CVE-2002-0773Proof of concept | imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imphosting controller · hosting controller | Критическая10,0 | — | 4,5 % | 12 авг. 2002 г. |
41В плане | CVE-2002-0465Эксплойта нет | Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbhosting controller · hosting controller | Критическая10,0 | — | 4,0 % | 12 авг. 2002 г. |
41В плане | CVE-2002-0774Эксплойта нет | Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the hosting controller · hosting controller | Критическая10,0 | — | 2,7 % | 12 авг. 2002 г. |
32Наблюдать | CVE-2005-1784Proof of concept | Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parhosting controller · hosting controller | Высокая7,5 | — | 5,6 % | 27 мая 2005 г. |
31Наблюдать | CVE-2006-5629Proof of concept | Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands hosting controller · hosting controller · CWE-89 | Высокая7,5 | — | 3,2 % | 31 окт. 2006 г. |
31Наблюдать | CVE-2007-6497Proof of concept | Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreshosting controller · hosting controller · CWE-264 | Высокая7,5 | — | 3,0 % | 20 дек. 2007 г. |
31Наблюдать | CVE-2005-1788Proof of concept | SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL chosting controller · hosting controller | Высокая7,5 | — | 2,1 % | 1 июн. 2005 г. |
31Наблюдать | CVE-2006-1229Эксплойта нет | SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands vhosting controller · hosting controller | Высокая7,5 | — | 1,9 % | 14 мар. 2006 г. |
31Наблюдать | CVE-2006-5630Эксплойта нет | Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified Forhosting controller · hosting controller | Высокая7,5 | — | 1,8 % | 31 окт. 2006 г. |
31Наблюдать | CVE-2002-0776Эксплойта нет | getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifyihosting controller · hosting controller | Высокая7,5 | — | 1,8 % | 12 авг. 2002 г. |
31Наблюдать | CVE-2006-1764Эксплойта нет | Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackershosting controller · hosting controller | Высокая7,8 | — | 1,6 % | 12 апр. 2006 г. |
30Наблюдать | CVE-2002-0212Эксплойта нет | The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows rhosting controller · hosting controller | Высокая7,5 | — | 1,6 % | 16 мая 2002 г. |
30Наблюдать | CVE-2007-6498Proof of concept | Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrahosting controller · hosting controller · CWE-89 | Высокая7,5 | — | 1,2 % | 20 дек. 2007 г. |
28Наблюдать | CVE-2002-0772Proof of concept | Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories vhosting controller · hosting controller | Средняя6,4 | — | 9,2 % | 12 авг. 2002 г. |
28Наблюдать | CVE-2007-6496Proof of concept | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp whosting controller · hosting controller · CWE-264 | Средняя6,8 | — | 2,7 % | 20 дек. 2007 г. |
27Наблюдать | CVE-2007-6495Proof of concept | inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directorieshosting controller · hosting controller · CWE-264 | Средняя6,5 | — | 4,4 % | 20 дек. 2007 г. |
27Наблюдать | CVE-2006-3147Proof of concept | Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privilehosting controller · hosting controller | Средняя6,5 | — | 2,7 % | 22 июн. 2006 г. |
27Наблюдать | CVE-2006-0581Эксплойта нет | SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via thehosting controller · hosting controller | Средняя6,5 | — | 1,8 % | 7 февр. 2006 г. |
26Наблюдать | CVE-2002-0464Эксплойта нет | Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and dirhosting controller · hosting controller | Средняя6,4 | — | 2,3 % | 12 авг. 2002 г. |
26Наблюдать | CVE-2006-6814Proof of concept | Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read andhosting controller · hosting controller | Средняя6,3 | — | 2,1 % | 29 дек. 2006 г. |
23Наблюдать | CVE-2007-6502Proof of concept | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and Ahosting controller · hosting controller · CWE-200 | Средняя5,5 | — | 2,8 % | 20 дек. 2007 г. |
23Наблюдать | CVE-2007-6499Proof of concept | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage exthosting controller · hosting controller · CWE-264 | Средняя5,5 | — | 2,5 % | 20 дек. 2007 г. |
23Наблюдать | CVE-2007-6501Proof of concept | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay typehosting controller · hosting controller · CWE-264 | Средняя5,5 | — | 2,4 % | 20 дек. 2007 г. |
23Наблюдать | CVE-2007-6503Proof of concept | Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbhosting controller · hosting controller · CWE-264 | Средняя5,5 | — | 2,2 % | 20 дек. 2007 г. |
- CVE-2007-649444В плане
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with
КритическаяCVSS 10,0Proof of conceptEPSS 12 %hosting controller · hosting controller20 дек. 2007 г.
- CVE-2002-077341В плане
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp
КритическаяCVSS 10,0Proof of conceptEPSS 4 %hosting controller · hosting controller12 авг. 2002 г.
- CVE-2002-046541В плане
Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arb
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %hosting controller · hosting controller12 авг. 2002 г.
- CVE-2002-077441В плане
Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %hosting controller · hosting controller12 авг. 2002 г.
- CVE-2005-178432Наблюдать
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress par
ВысокаяCVSS 7,5Proof of conceptEPSS 6 %hosting controller · hosting controller27 мая 2005 г.
- CVE-2006-562931Наблюдать
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %hosting controller · hosting controller31 окт. 2006 г.
- CVE-2007-649731Наблюдать
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addres
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %hosting controller · hosting controller20 дек. 2007 г.
- CVE-2005-178831Наблюдать
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL c
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %hosting controller · hosting controller1 июн. 2005 г.
- CVE-2006-122931Наблюдать
SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands v
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %hosting controller · hosting controller14 мар. 2006 г.
- CVE-2006-563031Наблюдать
Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified For
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %hosting controller · hosting controller31 окт. 2006 г.
- CVE-2002-077631Наблюдать
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifyi
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %hosting controller · hosting controller12 авг. 2002 г.
- CVE-2006-176431Наблюдать
Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %hosting controller · hosting controller12 апр. 2006 г.
- CVE-2002-021230Наблюдать
The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows r
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %hosting controller · hosting controller16 мая 2002 г.
- CVE-2007-649830Наблюдать
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitra
ВысокаяCVSS 7,5Proof of conceptEPSS 1 %hosting controller · hosting controller20 дек. 2007 г.
- CVE-2002-077228Наблюдать
Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories v
СредняяCVSS 6,4Proof of conceptEPSS 9 %hosting controller · hosting controller12 авг. 2002 г.
- CVE-2007-649628Наблюдать
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp w
СредняяCVSS 6,8Proof of conceptEPSS 3 %hosting controller · hosting controller20 дек. 2007 г.
- CVE-2007-649527Наблюдать
inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories
СредняяCVSS 6,5Proof of conceptEPSS 4 %hosting controller · hosting controller20 дек. 2007 г.
- CVE-2006-314727Наблюдать
Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privile
СредняяCVSS 6,5Proof of conceptEPSS 3 %hosting controller · hosting controller22 июн. 2006 г.
- CVE-2006-058127Наблюдать
SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the
СредняяCVSS 6,5Эксплойта нетEPSS 2 %hosting controller · hosting controller7 февр. 2006 г.
- CVE-2002-046426Наблюдать
Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and dir
СредняяCVSS 6,4Эксплойта нетEPSS 2 %hosting controller · hosting controller12 авг. 2002 г.
- CVE-2006-681426Наблюдать
Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and
СредняяCVSS 6,3Proof of conceptEPSS 2 %hosting controller · hosting controller29 дек. 2006 г.
- CVE-2007-650223Наблюдать
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and A
СредняяCVSS 5,5Proof of conceptEPSS 3 %hosting controller · hosting controller20 дек. 2007 г.
- CVE-2007-649923Наблюдать
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage ext
СредняяCVSS 5,5Proof of conceptEPSS 3 %hosting controller · hosting controller20 дек. 2007 г.
- CVE-2007-650123Наблюдать
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type
СредняяCVSS 5,5Proof of conceptEPSS 2 %hosting controller · hosting controller20 дек. 2007 г.
- CVE-2007-650323Наблюдать
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arb
СредняяCVSS 5,5Proof of conceptEPSS 2 %hosting controller · hosting controller20 дек. 2007 г.