Hosting Controller is a narrowly scoped hosting and server management platform whose small but recurring vulnerability footprint reflects the complexity of administrative interfaces managing distributed infrastructure. The vendor's disclosures cluster around a single flagship product, Hosting Controller and its HC10 variant, and recur through weakness classes including SQL injection, improper input validation, and exposure of sensitive information—patterns typical of web-facing administrative tooling. Notably, vulnerabilities affecting this vendor frequently acquire public exploit code, consistent with the appeal of administrative control planes as targets for post-compromise lateral movement and persistence. Defenders managing Hosting Controller instances should prioritize timely patching and restrict administrative access to trusted networks; live severity and current exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hosting Controller over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6494HIGH Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, fo | Dec 20, 2007 | 10.0 | 40 | NO | YES |
CVE-2019-12323HIGH The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS. | Jun 24, 2019 | 7.5 | 39 | NO | YES |
CVE-2002-0773HIGH imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters su | Aug 12, 2002 | 10.0 | 36 | NO | YES |
CVE-2002-0775MEDIUM browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter. | Aug 12, 2002 | 5.0 | 31 | NO | YES |
CVE-2005-1784HIGH Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for Us | May 27, 2005 | 7.5 | 30 | NO | YES |
CVE-2007-6497HIGH Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and em | Dec 20, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-5629HIGH Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) Disable | Oct 31, 2006 | 7.5 | 29 | NO | YES |
CVE-2002-0772MEDIUM Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (dot dot) in the RootName parame | Aug 12, 2002 | 6.4 | 29 | NO | YES |
CVE-2007-6498HIGH Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2 | Dec 20, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-1788HIGH SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter. | Jun 1, 2005 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hosting Controller.
Media articles that mention a CVE ID that affects a product developed by Hosting Controller — matched by CVE ID, not by vendor name.