Hosting Controller Unauthorized File Access and Upload Vulnerability
BID:3811
Info
Hosting Controller Unauthorized File Access and Upload Vulnerability
| Bugtraq ID: | 3811 |
| Class: | Access Validation Error |
| CVE: |
CVE-2002-0465 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 07 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | Discovered and posted to Bugtraq by Phuong Nguyen <[email protected]>. |
| Vulnerable: |
Hosting Controller Hosting Controller 1.4.1 |
| Not Vulnerable: | |
Discussion
Hosting Controller Unauthorized File Access and Upload Vulnerability
Hosting Controller is an application which centralizes all hosting tasks to one interface. Hosting Controller gives every user the required control they need to manage the appropriate web site relevant to them. Hosting Controller runs on Microsoft Windows systems.
Reportedly, an issue exists in Hosting Controller which could enable a user to read, delete and upload arbitrary files to the host.
Due to a flaw in filemanager.asp a user could exploit this issue by attempting to connect to an existing account and specifying '../' character sequences.
Hosting Controller is an application which centralizes all hosting tasks to one interface. Hosting Controller gives every user the required control they need to manage the appropriate web site relevant to them. Hosting Controller runs on Microsoft Windows systems.
Reportedly, an issue exists in Hosting Controller which could enable a user to read, delete and upload arbitrary files to the host.
Due to a flaw in filemanager.asp a user could exploit this issue by attempting to connect to an existing account and specifying '../' character sequences.
Exploit / POC
Hosting Controller Unauthorized File Access and Upload Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Hosting Controller Unauthorized File Access and Upload Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Hosting Controller Unauthorized File Access and Upload Vulnerability
References:
References:
- Hosting Controller Homepage (Hosting Controller)