PT-2005-1734 · Hosting Controller · Hosting Controller
(\\/) Mouse
+1
·
Published
2005-03-07
·
Updated
2016-10-18
·
CVE-2005-0694
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Hosting Controller versions 6.1 Hotfix 1.7 and earlier
Description
The issue allows remote attackers to obtain sensitive information via a direct request to "HCDiskQuotaService.csv". This is because log files are stored under the web root.
Recommendations
For Hosting Controller versions 6.1 Hotfix 1.7 and earlier, consider restricting access to the log files, specifically "HCDiskQuotaService.csv", to prevent remote attackers from obtaining sensitive information. As a temporary workaround, consider moving log files outside of the web root until a more permanent solution is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hosting Controller