PT-2005-1735 · Hosting Controller · Hosting Controller
(/) Mouse
+1
·
Publicado
2005-03-07
·
Atualizado
2016-10-18
·
CVE-2005-0695
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hosting Controller versions 6.1 Hotfix 1.7 and earlier
Description
The password recovery feature in the vulnerable software allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the
login ID field in the "forgotpassword.asp" page.Recommendations
For Hosting Controller versions 6.1 Hotfix 1.7 and earlier, consider disabling the password recovery feature or restricting access to the "forgotpassword.asp" page until a fix is available. As a temporary workaround, avoid using the
login ID field with partial domain names to minimize the risk of exploitation.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Hosting Controller