Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6497

Опубликовано: 20 дек. 2007
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote authenticated users to change a credit amount and increase a discount via an UpdateUser action to Accounts/AccountActions.asp with modified UserName, FullName, CreditLimit, and DefaultDiscount parameters, a related issue to CVE-2005-2219.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:hosting_controller:hosting_controller:*:*:*:*:*:*:*:*
Версия до 6.1_hotfix_3.3 (включая)

EPSS

Процентиль: 82%
0.01673
Низкий

7.5 High

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote authenticated users to change a credit amount and increase a discount via an UpdateUser action to Accounts/AccountActions.asp with modified UserName, FullName, CreditLimit, and DefaultDiscount parameters, a related issue to CVE-2005-2219.

EPSS

Процентиль: 82%
0.01673
Низкий

7.5 High

CVSS2

Дефекты

CWE-264