Vulnerability index

Browse CVEs

33 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Hosting Controller HIGH 10.0
CVE-2007-6494EPSS 12%

Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a usernam…

No fix yet
Fix from $1,950 2007-12-20
Hosting Controller HIGH 7.5
CVE-2007-6497

Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp…

Fix: after 6.1_hotfix_3.3
Fix from $1,950 2007-12-20
Hosting Controller HIGH 7.5
CVE-2007-6498

Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL co…

No fix yet
Fix from $1,950 2007-12-20
Hosting Controller MEDIUM 6.8
CVE-2007-6496

Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to hosting/addsubsite.asp with the l…

No fix yet
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 6.5
CVE-2007-6495

inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1…

No fix yet
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6499

Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to uninstall the FrontPage extensions o…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6501

Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable or disable "pay type" via a r…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6502

Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1) the AdminName and AdminLevel…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6503

Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to (1) import an arbitrary pl…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 5.5
CVE-2007-6504

Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the headers…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2007-12-20
Hosting Controller MEDIUM 6.3
CVE-2006-6814

Directory traversal vulnerability in FolderManager/FolderManager.aspx in Hosting Controller 7c allows remote authenticated users to read and modify a…

No fix yet
Fix from $1,600 2006-12-29
Hosting Controller HIGH 7.5
CVE-2006-5629

Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the F…

Fix: after 6.1_hotfix_3.2
Fix from $1,950 2006-10-31
Hosting Controller HIGH 7.5
CVE-2006-5630

Hosting Controller 6.1 before Hotfix 3.3 allows remote attackers to (1) delete the virtual directory of an arbitrary site via a modified ForumID para…

Fix: after 6.1_hotfix_3.2
Fix from $1,950 2006-10-31
Hosting Controller MEDIUM 6.5
CVE-2006-3147

Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list…

Patch available
Fix from $1,600 2006-06-22
Hosting Controller HIGH 7.8
CVE-2006-1764

Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtai…

Fix: after 6.1_hotfix_2.9
Fix from $1,950 2006-04-13
Hosting Controller MEDIUM 5.0
CVE-2006-1620

admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update…

Fix: after 6.1_hotfix_3.3
Fix from $1,600 2006-04-05
Hosting Controller HIGH 7.5
CVE-2006-1229

SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the se…

Mitigation only
Fix from $1,950 2006-03-14
Hosting Controller MEDIUM 6.5
CVE-2006-0581

SQL injection vulnerability in Hosting Controller 6.1 Hotfix 2.8 allows remote authenticated users to execute arbitrary SQL commands via the (1) Gate…

No fix yet
Fix from $1,600 2006-02-08
Hosting Controller MEDIUM 5.0
CVE-2005-3038

Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related …

Patch available
Fix from $1,600 2005-09-22
Hosting Controller HIGH 7.5
CVE-2005-1788

SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands v…

No fix yet
Fix from $1,950 2005-06-01
Hosting Controller HIGH 7.5
CVE-2005-1784EPSS 6%

Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in…

Fix: after 6.1_hotfix_2.0
Fix from $1,950 2005-05-27
Hosting Controller MEDIUM 5.0
CVE-2005-0694

Hosting Controller 6.1 Hotfix 1.7 and earlier stores log files under the web root, which allows remote attackers to obtain sensitive information via …

Patch available
Fix from $1,600 2005-03-07
Hosting Controller MEDIUM 5.0
CVE-2005-0695

The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's …

Patch available
Fix from $1,600 2005-03-07
Hosting Controller MEDIUM 5.0
CVE-2004-1217

Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathna…

No fix yet
Fix from $1,600 2005-01-10
Hosting Controller HIGH 10.0
CVE-2002-0465

Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary fi…

No fix yet
Fix from $1,950 2002-08-12
Hosting Controller HIGH 10.0
CVE-2002-0773

imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.…

Patch available
Fix from $1,950 2002-08-12
Hosting Controller HIGH 10.0
CVE-2002-0774

Hosting Controller creates a default user AdvWebadmin with a default password, which could allow remote attackers to gain privileges if the password …

Patch available
Fix from $1,950 2002-08-12
Hosting Controller HIGH 7.5
CVE-2002-0776

getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the us…

Patch available
Fix from $1,950 2002-08-12
Hosting Controller MEDIUM 6.4
CVE-2002-0464

Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories …

Mitigation only
Fix from $1,600 2002-08-12
Hosting Controller MEDIUM 6.4
CVE-2002-0772EPSS 9%

Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (…

Patch available
Fix from $1,600 2002-08-12