PT-2005-2631 · Hosting Controller · Hosting Controller

CVE-2005-1654

·

Publicado

2005-05-18

·

Atualizado

2024-01-25

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Hosting Controller versions 6.1 Hotfix 1.9 and earlier
Description The issue allows remote attackers to register arbitrary users via a direct request to "addsubsite.asp" with the loginname and password parameters set. This enables unauthorized access to the system.
Recommendations For Hosting Controller versions 6.1 Hotfix 1.9 and earlier, consider restricting access to the "addsubsite.asp" endpoint until a patch is available. As a temporary workaround, avoid using the loginname and password parameters in the affected endpoint to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2005-1654

Produtos afetados

Hosting Controller