Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pvjq-jfm7-jmrh

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.

admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.

EPSS

Процентиль: 78%
0.01141
Низкий

Связанные уязвимости

nvd
почти 20 лет назад

admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.

EPSS

Процентиль: 78%
0.01141
Низкий