hosting controller kayıtları
hosting controller üreticisine ait 37 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Yıllara göre kayıt
Çubuk: toplam · koyu kısım: CISA KEV.
Tekrar eden sınıflar
- CWE-264 Permissions, Privileges, and Access Controls8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-20 Improper Input Validation1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
37 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2007-6494Kavram kanıtı | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with hosting controller · hosting controller · CWE-20 | Kritik10,0 | — | %11,8 | 20 Ara 2007 |
41Planlayın | CVE-2002-0773Kavram kanıtı | imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imphosting controller · hosting controller | Kritik10,0 | — | %4,5 | 12 Ağu 2002 |
41Planlayın | CVE-2002-0465İstismar yok | Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbhosting controller · hosting controller | Kritik10,0 | — | %4,0 | 12 Ağu 2002 |
41Planlayın | CVE-2002-0774İstismar yok | Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the hosting controller · hosting controller | Kritik10,0 | — | %2,7 | 12 Ağu 2002 |
32İzleyin | CVE-2005-1784Kavram kanıtı | Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parhosting controller · hosting controller | Yüksek7,5 | — | %5,6 | 27 May 2005 |
31İzleyin | CVE-2006-5629Kavram kanıtı | Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands hosting controller · hosting controller · CWE-89 | Yüksek7,5 | — | %3,2 | 31 Eki 2006 |
31İzleyin | CVE-2007-6497Kavram kanıtı | Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreshosting controller · hosting controller · CWE-264 | Yüksek7,5 | — | %3,0 | 20 Ara 2007 |
31İzleyin | CVE-2005-1788Kavram kanıtı | SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL chosting controller · hosting controller | Yüksek7,5 | — | %2,1 | 1 Haz 2005 |
31İzleyin | CVE-2006-1229İstismar yok | SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands vhosting controller · hosting controller | Yüksek7,5 | — | %1,9 | 14 Mar 2006 |
31İzleyin | CVE-2006-5630İstismar yok | Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified Forhosting controller · hosting controller | Yüksek7,5 | — | %1,8 | 31 Eki 2006 |
31İzleyin | CVE-2002-0776İstismar yok | getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifyihosting controller · hosting controller | Yüksek7,5 | — | %1,8 | 12 Ağu 2002 |
31İzleyin | CVE-2006-1764İstismar yok | Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackershosting controller · hosting controller | Yüksek7,8 | — | %1,6 | 12 Nis 2006 |
30İzleyin | CVE-2002-0212İstismar yok | The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows rhosting controller · hosting controller | Yüksek7,5 | — | %1,6 | 16 May 2002 |
30İzleyin | CVE-2007-6498Kavram kanıtı | Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrahosting controller · hosting controller · CWE-89 | Yüksek7,5 | — | %1,2 | 20 Ara 2007 |
28İzleyin | CVE-2002-0772Kavram kanıtı | Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories vhosting controller · hosting controller | Orta6,4 | — | %9,2 | 12 Ağu 2002 |
28İzleyin | CVE-2007-6496Kavram kanıtı | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp whosting controller · hosting controller · CWE-264 | Orta6,8 | — | %2,7 | 20 Ara 2007 |
27İzleyin | CVE-2007-6495Kavram kanıtı | inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directorieshosting controller · hosting controller · CWE-264 | Orta6,5 | — | %4,4 | 20 Ara 2007 |
27İzleyin | CVE-2006-3147Kavram kanıtı | Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privilehosting controller · hosting controller | Orta6,5 | — | %2,7 | 22 Haz 2006 |
27İzleyin | CVE-2006-0581İstismar yok | SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via thehosting controller · hosting controller | Orta6,5 | — | %1,8 | 7 Şub 2006 |
26İzleyin | CVE-2002-0464İstismar yok | Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and dirhosting controller · hosting controller | Orta6,4 | — | %2,3 | 12 Ağu 2002 |
26İzleyin | CVE-2006-6814Kavram kanıtı | Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read andhosting controller · hosting controller | Orta6,3 | — | %2,1 | 29 Ara 2006 |
23İzleyin | CVE-2007-6502Kavram kanıtı | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and Ahosting controller · hosting controller · CWE-200 | Orta5,5 | — | %2,8 | 20 Ara 2007 |
23İzleyin | CVE-2007-6499Kavram kanıtı | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage exthosting controller · hosting controller · CWE-264 | Orta5,5 | — | %2,5 | 20 Ara 2007 |
23İzleyin | CVE-2007-6501Kavram kanıtı | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay typehosting controller · hosting controller · CWE-264 | Orta5,5 | — | %2,4 | 20 Ara 2007 |
23İzleyin | CVE-2007-6503Kavram kanıtı | Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbhosting controller · hosting controller · CWE-264 | Orta5,5 | — | %2,2 | 20 Ara 2007 |
- CVE-2007-649444Planlayın
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with
KritikCVSS 10,0Kavram kanıtıEPSS %12hosting controller · hosting controller20 Ara 2007
- CVE-2002-077341Planlayın
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp
KritikCVSS 10,0Kavram kanıtıEPSS %4hosting controller · hosting controller12 Ağu 2002
- CVE-2002-046541Planlayın
Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arb
KritikCVSS 10,0İstismar yokEPSS %4hosting controller · hosting controller12 Ağu 2002
- CVE-2002-077441Planlayın
Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the
KritikCVSS 10,0İstismar yokEPSS %3hosting controller · hosting controller12 Ağu 2002
- CVE-2005-178432İzleyin
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress par
YüksekCVSS 7,5Kavram kanıtıEPSS %6hosting controller · hosting controller27 May 2005
- CVE-2006-562931İzleyin
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5Kavram kanıtıEPSS %3hosting controller · hosting controller31 Eki 2006
- CVE-2007-649731İzleyin
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addres
YüksekCVSS 7,5Kavram kanıtıEPSS %3hosting controller · hosting controller20 Ara 2007
- CVE-2005-178831İzleyin
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL c
YüksekCVSS 7,5Kavram kanıtıEPSS %2hosting controller · hosting controller1 Haz 2005
- CVE-2006-122931İzleyin
SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands v
YüksekCVSS 7,5İstismar yokEPSS %2hosting controller · hosting controller14 Mar 2006
- CVE-2006-563031İzleyin
Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified For
YüksekCVSS 7,5İstismar yokEPSS %2hosting controller · hosting controller31 Eki 2006
- CVE-2002-077631İzleyin
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifyi
YüksekCVSS 7,5İstismar yokEPSS %2hosting controller · hosting controller12 Ağu 2002
- CVE-2006-176431İzleyin
Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers
YüksekCVSS 7,8İstismar yokEPSS %2hosting controller · hosting controller12 Nis 2006
- CVE-2002-021230İzleyin
The login for Hosting Controller 1.1 through 1.4.1 returns different error messages when a valid or invalid user is provided, which allows r
YüksekCVSS 7,5İstismar yokEPSS %2hosting controller · hosting controller16 May 2002
- CVE-2007-649830İzleyin
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitra
YüksekCVSS 7,5Kavram kanıtıEPSS %1hosting controller · hosting controller20 Ara 2007
- CVE-2002-077228İzleyin
Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories v
OrtaCVSS 6,4Kavram kanıtıEPSS %9hosting controller · hosting controller12 Ağu 2002
- CVE-2007-649628İzleyin
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp w
OrtaCVSS 6,8Kavram kanıtıEPSS %3hosting controller · hosting controller20 Ara 2007
- CVE-2007-649527İzleyin
inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories
OrtaCVSS 6,5Kavram kanıtıEPSS %4hosting controller · hosting controller20 Ara 2007
- CVE-2006-314727İzleyin
Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privile
OrtaCVSS 6,5Kavram kanıtıEPSS %3hosting controller · hosting controller22 Haz 2006
- CVE-2006-058127İzleyin
SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the
OrtaCVSS 6,5İstismar yokEPSS %2hosting controller · hosting controller7 Şub 2006
- CVE-2002-046426İzleyin
Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and dir
OrtaCVSS 6,4İstismar yokEPSS %2hosting controller · hosting controller12 Ağu 2002
- CVE-2006-681426İzleyin
Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and
OrtaCVSS 6,3Kavram kanıtıEPSS %2hosting controller · hosting controller29 Ara 2006
- CVE-2007-650223İzleyin
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and A
OrtaCVSS 5,5Kavram kanıtıEPSS %3hosting controller · hosting controller20 Ara 2007
- CVE-2007-649923İzleyin
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage ext
OrtaCVSS 5,5Kavram kanıtıEPSS %3hosting controller · hosting controller20 Ara 2007
- CVE-2007-650123İzleyin
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type
OrtaCVSS 5,5Kavram kanıtıEPSS %2hosting controller · hosting controller20 Ara 2007
- CVE-2007-650323İzleyin
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arb
OrtaCVSS 5,5Kavram kanıtıEPSS %2hosting controller · hosting controller20 Ara 2007