PT-2006-7411 · Hosting Controller · Hosting Controller

Publicado

2006-12-29

·

Atualizado

2011-03-08

·

CVE-2006-6814

CVSS v2.0

6.3

Média

VetorAV:N/AC:M/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Hosting Controller version 7c
Description: A directory traversal issue exists, allowing remote authenticated users to read and modify arbitrary files and list directories via .. sequences in the BrowsePath parameter.
Recommendations: For version 7c, consider restricting access to the FolderManager/FolderManager.aspx page until a patch is available, and avoid using the BrowsePath parameter with untrusted input to minimize the risk of exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-6814

Produtos afetados

Hosting Controller