Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
References
Link Resource
http://isun.shabgard.org/hc3.txt Broken Link Exploit Patch
http://secunia.com/advisories/15271 Broken Link
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:22:41

Updated: 2022-10-03T16:22:41

Reserved: 2022-10-03T00:00:00


Link: CVE-2005-1654

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2005-05-18T04:00:00.000

Modified: 2024-01-25T21:03:52.843


Link: CVE-2005-1654

JSON object: View

cve-icon Redhat Information

No data.

CWE