CVE-2007-6495 describes a vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier, where an authenticated attacker can manipulate directory permissions. By modifying the Dirroot parameter in an AddUser action, attackers can change permissions for specific directories, including those configured for ASP script execution with administrative privileges. This medium-severity vulnerability (CVSS 6.5) allows for potential remote code execution, as demonstrated by changing permissions for the \Forum\db directory and uploading malicious scripts. While exploit code exists in ExploitDB, there is no evidence of active exploitation, Metasploit modules, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.1_hotfix_3.3CPE matchmatch criteria | cpe:2.3:a:hosting_controller:hosting_controller:6.1_hotfix_3.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:S/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.