Hosting Controller Information Disclosure Vulnerability
BID:3971
Info
Hosting Controller Information Disclosure Vulnerability
| Bugtraq ID: | 3971 |
| Class: | Design Error |
| CVE: |
CVE-2002-0212 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 26 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was submitted to BugTraq on January 26th, 2002 by Ahmet Sabri ALPER <[email protected]>. |
| Vulnerable: |
Hosting Controller Hosting Controller 1.4.1 Hosting Controller Hosting Controller 1.4 b Hosting Controller Hosting Controller 1.4 Hosting Controller Hosting Controller 1.3 Hosting Controller Hosting Controller 1.1 |
| Not Vulnerable: | |
Discussion
Hosting Controller Information Disclosure Vulnerability
Hosting Controller is an application which centralizes all hosting tasks to one interface. Hosting Controller gives every user the required control they need to manage the appropriate web site relevant to them. Hosting Controller runs on Microsoft Windows systems.
An issue has been discovered in Hosting Controller which may make it easier for remote attackers to brute-force user accounts. When a user enters an invalid username, Hosting Controller gives the following feedback:
"The user name could not be found"
This allows the attacker to determine which usernames are valid. The attacker may then attempt a brute-force attack in an attempt to crack the passwords of valid usernames.
Hosting Controller is an application which centralizes all hosting tasks to one interface. Hosting Controller gives every user the required control they need to manage the appropriate web site relevant to them. Hosting Controller runs on Microsoft Windows systems.
An issue has been discovered in Hosting Controller which may make it easier for remote attackers to brute-force user accounts. When a user enters an invalid username, Hosting Controller gives the following feedback:
"The user name could not be found"
This allows the attacker to determine which usernames are valid. The attacker may then attempt a brute-force attack in an attempt to crack the passwords of valid usernames.
Exploit / POC
Hosting Controller Information Disclosure Vulnerability
No exploit code is required.
No exploit code is required.
Solution / Fix
Hosting Controller Information Disclosure Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Hosting Controller Information Disclosure Vulnerability
References:
References:
- Hosting Controller Homepage (Hosting Controller)