PT-2006-2245 · Hosting Controller · Hosting Controller
Published
2006-03-14
·
Updated
2017-07-20
·
CVE-2006-1229
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Hosting Controller version 6.1 (Hotfix 2.9)
Description
A SQL injection issue allows remote attackers to execute arbitrary SQL commands via the
search parameter in the "search.asp" page.Recommendations
For Hosting Controller version 6.1 (Hotfix 2.9), avoid using the
search parameter in the affected "search.asp" page until a fix is available. Consider restricting access to the "search.asp" page as a temporary workaround to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Hosting Controller