vendor:
by:
www.BugReport.ir
9
CVSS
CRITICAL
Multiple Security Bugs
CWE
Product Name:
Affected Version From: 6.1 Hot fix
Affected Version To: 3.3
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested:
2007
Multiple Security Bugs In Hosting Controller
Multiple security bugs in Hosting Controller allow a remote attacker to gain full system administrator access. The attacker can login to the hosting controller panel, change passwords, execute commands with administrative privilege, create new users, change user profiles, perform SQL injection to access database information, manipulate credit amounts and discounts, uninstall FrontPage extensions, delete gateway information, enable or disable payment types, reveal usernames, find hosting controller setup directory, import unwanted plans, find web site path, and enable or disable forums. These vulnerabilities can be exploited by unauthorized users and users with simple accounts.
Mitigation:
N/A From company - There is temporary solution in this report