Hosting Controller Multiple Information Disclosure Vulnerabilities
BID:12748
Info
Hosting Controller Multiple Information Disclosure Vulnerabilities
| Bugtraq ID: | 12748 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2005 12:00AM |
| Updated: | Mar 07 2005 12:00AM |
| Credit: | Discovery is credited to small mouse <[email protected]>. |
| Vulnerable: |
Hosting Controller Hosting Controller 6.1 Hotfix 1.7 Hosting Controller Hosting Controller 6.1 Hotfix 1.4 Hosting Controller Hosting Controller 6.1 Hosting Controller Hosting Controller 1.4.1 Hosting Controller Hosting Controller 1.4 b Hosting Controller Hosting Controller 1.4 Hosting Controller Hosting Controller 1.3 Hosting Controller Hosting Controller 1.1 |
| Not Vulnerable: | |
Discussion
Hosting Controller Multiple Information Disclosure Vulnerabilities
Hosting Controller is reported prone to multiple information disclosure vulnerabilities. These issues can allow an attacker to disclose sensitive information, which may be used to carry out further attacks against a computer.
An attacker can access a sensitive file to enumerate domain names of all hosted domains.
Another issue affecting the application may allow remote users to disclose an administrator's email address.
These issues are reported to affect Hosting Controller 6.1 Hotfix 1.7. Other versions are likely to be affected as well.
Hosting Controller is reported prone to multiple information disclosure vulnerabilities. These issues can allow an attacker to disclose sensitive information, which may be used to carry out further attacks against a computer.
An attacker can access a sensitive file to enumerate domain names of all hosted domains.
Another issue affecting the application may allow remote users to disclose an administrator's email address.
These issues are reported to affect Hosting Controller 6.1 Hotfix 1.7. Other versions are likely to be affected as well.
Exploit / POC
Hosting Controller Multiple Information Disclosure Vulnerabilities
An exploit is not required.
The following proof of concept is available:
http://www.example.com/admin/logs/HCDiskQuotaService.csv
An exploit is not required.
The following proof of concept is available:
http://www.example.com/admin/logs/HCDiskQuotaService.csv
Solution / Fix
Hosting Controller Multiple Information Disclosure Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Hosting Controller Multiple Information Disclosure Vulnerabilities
References:
References:
- Hosting Controller Homepage (Hosting Controller)
- Hosting Controller Multiple Unauthenticated information disclose (small mouse
)