Hosting Controller Error.ASP Cross-site Scripting Vulnerability
BID:18933
Info
Hosting Controller Error.ASP Cross-site Scripting Vulnerability
| Bugtraq ID: | 18933 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 11 2006 12:00AM |
| Updated: | Jul 12 2006 07:53PM |
| Credit: | Dea7h is credited with discovering this vulnerability. |
| Vulnerable: |
Hosting Controller Hosting Controller 6.1.0 Hotfix 3.2 0 Hosting Controller Hosting Controller 6.1.0 Hotfix 3.1 0 Hosting Controller Hosting Controller 2002 Hosting Controller Hosting Controller 6.1 Hotfix 2.4 Hosting Controller Hosting Controller 6.1 Hotfix 2.3 Hosting Controller Hosting Controller 6.1 Hotfix 2.2 Hosting Controller Hosting Controller 6.1 Hotfix 2.1 Hosting Controller Hosting Controller 6.1 Hotfix 2.0 Hosting Controller Hosting Controller 6.1 Hotfix 1.9 Hosting Controller Hosting Controller 6.1 Hotfix 1.7 Hosting Controller Hosting Controller 6.1 Hotfix 1.4 Hosting Controller Hosting Controller 6.1 Hosting Controller Hosting Controller 1.4.1 Hosting Controller Hosting Controller 1.4 b Hosting Controller Hosting Controller 1.4 Hosting Controller Hosting Controller 1.3 Hosting Controller Hosting Controller 1.1 Hosting Controller Hosting Controller 6.1.Hotfix 2.8 |
| Not Vulnerable: | |
Discussion
Hosting Controller Error.ASP Cross-site Scripting Vulnerability
Hosting Controller is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks
Versions 6.1 and prior are affected.
Hosting Controller is prone to a cross-site scripting vulnerability because it fails to sanitize input before displaying it to users of the application.
An attacker may leverage this issue to have arbitrary script code execute in the browser of an unsuspecting user in the context of the affected site. This may help the attacker steal cookie-based authentication credentials and launch other attacks
Versions 6.1 and prior are affected.
Exploit / POC
Hosting Controller Error.ASP Cross-site Scripting Vulnerability
Attackers can exploit this issue via a web-client.
The following proof-of-concept URI is available:
Attackers can exploit this issue via a web-client.
The following proof-of-concept URI is available:
Solution / Fix
Hosting Controller Error.ASP Cross-site Scripting Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please email us at: [email protected]:[email protected].
References
Hosting Controller Error.ASP Cross-site Scripting Vulnerability
References:
References:
- Hosting Controller Home Page (Hosting Controller)