Virtual Hosting Control System is a narrowly scoped hosting management platform that, despite its focused product footprint, occupies a prominent position in the vulnerability landscape, likely reflecting its deep embedding in web-hosting infrastructure. The recurring exposure centers on authentication and access-control deficiencies that are characteristic of administrative interfaces managing server and customer accounts; public exploit code is frequently available for disclosed flaws in this product. Current severity, exploitation, and coverage details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Virtual Hosting Control System over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2006-0685HIGH The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain un | Feb 15, 2006 | 10.0 | 36 | NO | YES |
CVE-2006-0684HIGH change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers | Feb 15, 2006 | 7.5 | 29 | NO | YES |
CVE-2006-0686HIGH add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gai | Feb 15, 2006 | 10.0 | 25 | NO | NO |
CVE-2006-2174MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or | May 4, 2006 | 4.3 | 21 | NO | YES |
CVE-2005-3902MEDIUM Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web s | Nov 29, 2005 | 4.3 | 21 | NO | YES |
CVE-2005-1128HIGH Multiple SQL injection vulnerabilities in VHCS 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via certain inputs from HTTP POST queries. | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2007-3988MEDIUM Session fixation vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier allows remote attackers to hijack web sessions by setting the PHPSESSID parameter. | Jul 25, 2007 | 6.8 | 18 | NO | NO |
CVE-2006-0683MEDIUM Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML | Feb 15, 2006 | 4.3 | 14 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Virtual Hosting Control System.
Media articles that mention a CVE ID that affects a product developed by Virtual Hosting Control System — matched by CVE ID, not by vendor name.