Hosting Controller / Hosting Controller
38 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2007-6504 | Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers of arbitr… | MEDIUM | 5.5 | Dec 20, 2007 |
| CVE-2007-6503 | Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary plan via a r… | MEDIUM | 5.5 | Dec 20, 2007 |
| CVE-2007-6502 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel parameter… | MEDIUM | 5.5 | Dec 20, 2007 |
| CVE-2007-6501 | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a request to… | MEDIUM | 5.5 | Dec 20, 2007 |
| CVE-2007-6500 | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete "gateway information" via a request to… | MEDIUM | 4.9 | Dec 20, 2007 |
| CVE-2007-6499 | Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions of an arbit… | MEDIUM | 5.5 | Dec 20, 2007 |
| CVE-2007-6498 | Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via… | HIGH | 7.5 | Dec 20, 2007 |
| CVE-2007-6497 | Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modi… | HIGH | 7.5 | Dec 20, 2007 |
| CVE-2007-6496 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the loginname a… | MEDIUM | 6.8 | Dec 20, 2007 |
| CVE-2007-6495 | inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2)… | MEDIUM | 6.5 | Dec 20, 2007 |
| CVE-2007-6494 | Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the r… | HIGH | 10.0 | Dec 20, 2007 |
| CVE-2006-6814 | Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify arbitrary f… | MEDIUM | 6.3 | Dec 29, 2006 |
| CVE-2006-5630 | Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified ForumID parameter in a… | HIGH | 7.5 | Oct 31, 2006 |
| CVE-2006-5629 | Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID par… | HIGH | 7.5 | Oct 31, 2006 |
| CVE-2006-3147 | Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resel… | MEDIUM | 6.5 | Jun 22, 2006 |
| CVE-2006-1764 | Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitiv… | HIGH | 7.8 | Apr 13, 2006 |
| CVE-2006-1621 | Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary… | MEDIUM | 4.0 | Apr 5, 2006 |
| CVE-2006-1620 | admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" Act… | MEDIUM | 5.0 | Apr 5, 2006 |
| CVE-2006-1229 | SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search param… | HIGH | 7.5 | Mar 14, 2006 |
| CVE-2006-0581 | SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) GatewayID para… | MEDIUM | 6.5 | Feb 8, 2006 |
| CVE-2005-3038 | Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PH… | MEDIUM | 5.0 | Sep 22, 2005 |
| CVE-2005-2219 | Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request t… | MEDIUM | 4.6 | Jul 12, 2005 |
| CVE-2005-2077 | Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error param… | MEDIUM | 4.3 | Jun 29, 2005 |
| CVE-2005-1788 | SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jre… | HIGH | 7.5 | Jun 1, 2005 |
| CVE-2005-1784 | Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an update… | HIGH | 7.5 | May 31, 2005 |
Showing 1 to 25 of 38 CVEs