Hosting Controller Multiple Remote Access Control and SQL Injection Vulnerabilities
BID:14302
Info
Hosting Controller Multiple Remote Access Control and SQL Injection Vulnerabilities
| Bugtraq ID: | 14302 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 18 2005 12:00AM |
| Updated: | Jul 18 2005 12:00AM |
| Credit: | Discovery is credited to Soroush Dalili with GrayHatz Security Group. |
| Vulnerable: |
Hosting Controller Hosting Controller 6.1 Hotfix 2.2 |
| Not Vulnerable: | |
Discussion
Hosting Controller Multiple Remote Access Control and SQL Injection Vulnerabilities
Hosting Controller is prone to multiple vulnerabilities. These issues can allow an attacker to carry out SQL injection attacks and gain unauthorized access to scripts.
Hosting Controller version 6.1 hotfix 2.2 is vulnerable to these issues.
Hosting Controller is prone to multiple vulnerabilities. These issues can allow an attacker to carry out SQL injection attacks and gain unauthorized access to scripts.
Hosting Controller version 6.1 hotfix 2.2 is vulnerable to these issues.
Exploit / POC
Hosting Controller Multiple Remote Access Control and SQL Injection Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Hosting Controller Multiple Remote Access Control and SQL Injection Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Hosting Controller Multiple Remote Access Control and SQL Injection Vulnerabilities
References:
References:
- Hosting Controller Homepage (Hosting Controller)