HIGH
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote authenticated users to change a credit amount and increase a discount via an UpdateUser action to Accounts/AccountActions.asp with modified UserName, FullName, CreditLimit, and DefaultDiscount parameters, a related issue to CVE-2005-2219
Published Dec 20, 2007
7.5
HIGHCVSS 2.0
EPSS 2.96%
Description
Affected products
Remediation
Metrics
References (7)
Change history (0)
No recorded changes yet.