Hostingcontroller develops a web hosting control panel product used by service providers to manage customer accounts and server resources, with identified vulnerabilities centered on access-control and memory-safety issues such as direct request exploitation and out-of-bounds writes. Treat this as a compact vendor profile; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Hostingcontroller over time
Signals from CVEs in this vendor scope (39 CVEs).
39 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-6494HIGH Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, fo | Dec 20, 2007 | 10.0 | 40 | NO | YES |
CVE-2019-12323HIGH The HC.Server service in Hosting Controller HC10 10.14 allows an Invalid Pointer Write DoS. | Jun 24, 2019 | 7.5 | 39 | NO | YES |
CVE-2002-0773HIGH imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters su | Aug 12, 2002 | 10.0 | 36 | NO | YES |
CVE-2002-0775MEDIUM browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter. | Aug 12, 2002 | 5.0 | 31 | NO | YES |
CVE-2005-1784HIGH Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for Us | May 27, 2005 | 7.5 | 30 | NO | YES |
CVE-2007-6497HIGH Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and em | Dec 20, 2007 | 7.5 | 29 | NO | YES |
CVE-2006-5629HIGH Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) Disable | Oct 31, 2006 | 7.5 | 29 | NO | YES |
CVE-2002-0772MEDIUM Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (dot dot) in the RootName parame | Aug 12, 2002 | 6.4 | 29 | NO | YES |
CVE-2007-6498HIGH Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2 | Dec 20, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-1788HIGH SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter. | Jun 1, 2005 | 7.5 | 28 | NO | YES |
Signals from CVEs in this vendor scope (39 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Hostingcontroller.
Media articles that mention a CVE ID that affects a product developed by Hostingcontroller — matched by CVE ID, not by vendor name.