PT-2005-1735 · Hosting Controller · Hosting Controller

(/) Mouse

+1

·

Published

2005-03-07

·

Updated

2016-10-18

·

CVE-2005-0695

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Hosting Controller versions 6.1 Hotfix 1.7 and earlier
Description The password recovery feature in the vulnerable software allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the login ID field in the "forgotpassword.asp" page.
Recommendations For Hosting Controller versions 6.1 Hotfix 1.7 and earlier, consider disabling the password recovery feature or restricting access to the "forgotpassword.asp" page until a fix is available. As a temporary workaround, avoid using the login ID field with partial domain names to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0695

Affected Products

Hosting Controller