Hosting Controller
hosting_controller
37 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (37)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 5.5 MEDIUM· v2 Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers of arbitrary hosts via an unspecified parameter. |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 5.5 MEDIUM· v2 Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary plan via a request to hosting/importhostingplans.asp; or (2) change an ar...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 5.5 MEDIUM· v2 Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameters to fp2000/NEWSRVR.asp, which discloses usernames; and (2) c...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 5.5 MEDIUM· v2 Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a request to adminsettings/choosetranstype.asp. |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 4.9 MEDIUM· v2 Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a request to OpenApi/GatewayVariables.asp. |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 5.5 MEDIUM· v2 Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions of an arbitrary account via a request to fp2002/UNINSTAL.asp with a "hos...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2) loginname parameters to Hosting/Addres...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 7.5 HIGH· v2 Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote au...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname and password parameters set, when preceded by certain requests...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 6.5 MEDIUM· v2 inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2) www, (3) Special, and (4) log at arbitrary locations under th...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 20, 2007 N/A· v4 N/A· v3 10.0 HIGH· v2 Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/dis...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Dec 29, 2006 N/A· v4 N/A· v3 6.3 MEDIUM· v2 Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary files, and list arbitrary directories via ..\ (dot dot backsla...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Oct 31, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified ForumID parameter in a disableforum action in DisableForum.asp and (2) create an ar...Show more |
1Hosting Controller 1Hosting Controller Apr 23, 2026 Oct 31, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE...Show more |
1Hosting Controller 1Hosting Controller Apr 16, 2026 Jun 22, 2006 N/A· v4 N/A· v3 6.5 MEDIUM· v2 Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resellers, or change resellers' passwords via unspecified vectors....Show more |
1Hosting Controller 1Hosting Controller Apr 16, 2026 Apr 13, 2006 N/A· v4 N/A· v3 7.8 HIGH· v2 Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials. NO...Show more |
1Hosting Controller 1Hosting Controller Apr 16, 2026 Apr 5, 2006 N/A· v4 N/A· v3 4.0 MEDIUM· v2 Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary files via an absolute path in the OpenPath parameter. |
1Hosting Controller 1Hosting Controller Apr 16, 2026 Apr 5, 2006 N/A· v4 N/A· v3 5.0 MEDIUM· v2 admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck...Show more |
1Hosting Controller 1Hosting Controller Apr 16, 2026 Mar 14, 2006 N/A· v4 N/A· v3 7.5 HIGH· v2 SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; t...Show more |
1Hosting Controller 1Hosting Controller Apr 16, 2026 Feb 8, 2006 N/A· v4 N/A· v3 6.5 MEDIUM· v2 SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID parameter in an add action in AddGatewaySettings.asp and (2) IP p...Show more |