CVE-2005-1654

Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
References
Link Resource
http://isun.shabgard.org/hc3.txt Broken Link Exploit Patch
http://secunia.com/advisories/15271 Broken Link
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:hostingcontroller:hosting_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:-:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.0:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.1:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.2:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.3:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.4:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.5:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.6:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.7:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.8:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.9:*:*:*:*:*:*

History

25 Jan 2024, 21:03

Type Values Removed Values Added
References () http://isun.shabgard.org/hc3.txt - Exploit, Patch () http://isun.shabgard.org/hc3.txt - Broken Link, Exploit, Patch
References () http://secunia.com/advisories/15271 - () http://secunia.com/advisories/15271 - Broken Link
CPE cpe:2.3:a:hosting_controller:hosting_controller:6.1_hotfix_1.9:*:*:*:*:*:*:*
cpe:2.3:a:hosting_controller:hosting_controller:6.1_hotfix_1.4:*:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.1:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.5:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:-:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.8:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.7:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.3:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.6:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.9:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.4:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.0:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:*:*:*:*:*:*:*:*
cpe:2.3:a:hostingcontroller:hosting_controller:6.1:hotfix1.2:*:*:*:*:*:*
CWE NVD-CWE-Other CWE-425
First Time Hostingcontroller hosting Controller
Hostingcontroller

Information

Published : 2005-05-18 04:00

Updated : 2024-01-25 21:03


NVD link : CVE-2005-1654

Mitre link : CVE-2005-1654

CVE.ORG link : CVE-2005-1654


JSON object : View

Products Affected

hostingcontroller

  • hosting_controller
CWE
CWE-425

Direct Request ('Forced Browsing')