Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Mouse

Pesquisador deShabgard.org
#49470de 53,622
5CVSS total
Vulnerabilidades · 1
PT-2004-2165
5.0
2004-12-15
Hosting Controller · Hosting Controller · CVE-2004-1217
Name of the Vulnerable Software and Affected Versions: Hosting Controller version 6.1 Hotfix 1.4 Description: The issue allows remote attackers to view arbitrary directories by specifying the target pathname in the `FilePath` parameter to API endpoints such as "Statsbrowse.asp" or "Generalbrowse.asp". Recommendations: For Hosting Controller version 6.1 Hotfix 1.4, avoid using the `FilePath` parameter in the affected API endpoints until the issue is resolved. Restrict access to the "Statsbrowse.asp" and "Generalbrowse.asp" pages to minimize the risk of exploitation.