PT-2005-1735 · Hosting Controller · Hosting Controller

(/) Mouse

+1

·

Publicado

2005-03-07

·

Atualizado

2016-10-18

·

CVE-2005-0695

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hosting Controller versions 6.1 Hotfix 1.7 and earlier
Description The password recovery feature in the vulnerable software allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the login ID field in the "forgotpassword.asp" page.
Recommendations For Hosting Controller versions 6.1 Hotfix 1.7 and earlier, consider disabling the password recovery feature or restricting access to the "forgotpassword.asp" page until a fix is available. As a temporary workaround, avoid using the login ID field with partial domain names to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-0695

Produtos afetados

Hosting Controller