CVE-2002-0776

getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.
Configurations

Configuration 1 (hide)

cpe:2.3:a:hosting_controller:hosting_controller:2002:*:*:*:*:*:*:*

History

20 Nov 2024, 23:39

Type Values Removed Values Added
References () http://hostingcontroller.com/english/logs/sp2log.html - Patch, Vendor Advisory () http://hostingcontroller.com/english/logs/sp2log.html - Patch, Vendor Advisory
References () http://online.securityfocus.com/archive/1/282129 - Exploit, Patch, Vendor Advisory () http://online.securityfocus.com/archive/1/282129 - Exploit, Patch, Vendor Advisory
References () http://www.iss.net/security_center/static/9554.php - () http://www.iss.net/security_center/static/9554.php -
References () http://www.securityfocus.com/bid/5229 - () http://www.securityfocus.com/bid/5229 -

Information

Published : 2002-08-12 04:00

Updated : 2024-11-20 23:39


NVD link : CVE-2002-0776

Mitre link : CVE-2002-0776

CVE.ORG link : CVE-2002-0776


JSON object : View

Products Affected

hosting_controller

  • hosting_controller