Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
HIGH 10.0
CVE-2007-6494EPSS 12%
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a usernam…
Hosting Controller
No fix yet
HIGH 7.5
CVE-2007-6497
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp…
Hosting Controller
after 6.1_hotfix_3.3
HIGH 7.5
CVE-2007-6498
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL co…
Hosting Controller
No fix yet
MEDIUM 6.8
CVE-2007-6496
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the l…
Hosting Controller
No fix yet
MEDIUM 6.5
CVE-2007-6495
inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1…
Hosting Controller
No fix yet
MEDIUM 5.5
CVE-2007-6499
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions o…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 5.5
CVE-2007-6501
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a r…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 5.5
CVE-2007-6502
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 5.5
CVE-2007-6503
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary pl…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 5.5
CVE-2007-6504
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers…
Hosting Controller
after 6.1_hotfix_3.3
MEDIUM 6.3
CVE-2006-6814
Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify a…
Hosting Controller
No fix yet
HIGH 7.5
CVE-2006-5629
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the F…
Hosting Controller
after 6.1_hotfix_3.2
HIGH 7.5
CVE-2006-5630
Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified ForumID para…
Hosting Controller
after 6.1_hotfix_3.2
MEDIUM 6.5
CVE-2006-3147
Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list…
Hosting Controller
Patch available
HIGH 7.8
CVE-2006-1764
Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtai…
Hosting Controller
after 6.1_hotfix_2.9
MEDIUM 5.0
CVE-2006-1620
admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update…
Hosting Controller
after 6.1_hotfix_3.3
HIGH 7.5
CVE-2006-1229
SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the se…
Hosting Controller
Mitigation only
MEDIUM 6.5
CVE-2006-0581
SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) Gate…
Hosting Controller
No fix yet
MEDIUM 5.0
CVE-2005-3038
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related …
Hosting Controller
Patch available
HIGH 7.5
CVE-2005-1788
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands v…
Hosting Controller
No fix yet
HIGH 7.5
CVE-2005-1784EPSS 6%
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in…
Hosting Controller
after 6.1_hotfix_2.0
MEDIUM 5.0
CVE-2005-0694
Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via …
Hosting Controller
Patch available
MEDIUM 5.0
CVE-2005-0695
The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's …
Hosting Controller
Patch available
MEDIUM 5.0
CVE-2004-1217
Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathna…
Hosting Controller
No fix yet
HIGH 10.0
CVE-2002-0465
Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary fi…
Hosting Controller
No fix yet
HIGH 10.0
CVE-2002-0773
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.…
Hosting Controller
Patch available
HIGH 10.0
CVE-2002-0774
Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password …
Hosting Controller
Patch available
HIGH 7.5
CVE-2002-0776
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the us…
Hosting Controller
Patch available
MEDIUM 6.4
CVE-2002-0464
Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories …
Hosting Controller
Mitigation only
MEDIUM 6.4
CVE-2002-0772EPSS 9%
Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (…
Hosting Controller
Patch available