Hosting Controller

Vendor:

First CVE: May 16, 2002 · Active for 24 years

38
Total CVEs
Bottom 1%
9.5
Avg CVEs / Year
Bottom 1%
6.5
Avg CVSS
Higher Avg CVSS than 50% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Hosting Controller over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2002
24 years ago
Most Recent CVE
Dec 20, 2007
6,791 days ago

CVE Severity & Scoring

Hosting Controller38 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown38 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown38 (100.0%)
User Interaction
None0 (0.0%)
Unknown38 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown38 (100.0%)

Top CVEs

Signals from CVEs in this product scope (38 CVEs).

38 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, fo
Dec 20, 200710.040NOYES
imp_rootdir.asp for Hosting Controller allows remote attackers to copy or delete arbitrary files and directories via a direct request to imp_rootdir.asp and modifying parameters su
Aug 12, 200210.036NOYES
browse.asp in Hosting Controller allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter.
Aug 12, 20025.031NOYES
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for Us
May 27, 20057.530NOYES
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and em
Dec 20, 20077.529NOYES
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) Disable
Oct 31, 20067.529NOYES
Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote attackers to read arbitrary files and directories via a .. (dot dot) in the RootName parame
Aug 12, 20026.429NOYES
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) email and (2
Dec 20, 20077.528NOYES
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.
Jun 1, 20057.528NOYES
Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters
May 18, 20057.528NOYES

Exploit Exposure

Signals from CVEs in this product scope (38 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
23 CVEs
60.5% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (38 CVEs).

Media Mentions

Signals from CVEs in this product scope (38 CVEs).

Top CNAs Publishing CVEs For Hosting Controller

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7c16.31.9%01
6.1_hotfix_3.347.75.0%04
6.1_hotfix_3.127.52.4%01
6.1_hotfix_2.927.01.9%01
6.1_hotfix_2.836.92.0%01
6.1_hotfix_2.427.52.4%01
6.1_hotfix_2.356.92.1%02
6.1_hotfix_2.227.52.4%01
6.1_hotfix_2.156.82.2%03
6.1_hotfix_2.066.82.5%04
6.1_hotfix_1.956.72.5%03
6.1_hotfix_1.776.22.2%03
6.1_hotfix_1.486.12.3%04
6.196.22.3%05
2002_rc_156.42.0%01
200247.62.1%01
1.4b116.93.6%05
1.4.1147.03.4%05
1.4127.33.7%05
1.3116.93.6%05