6.4
CVSSv2

CVE-2002-0772

Published: 12/08/2002 Updated: 05/09/2008
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in dsnmanager.asp for Hosting Controller allows remote malicious users to read arbitrary files and directories via a .. (dot dot) in the RootName parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

hosting controller hosting controller 1.4b

hosting controller hosting controller 1.1

hosting controller hosting controller 1.3

hosting controller hosting controller 1.4

hosting controller hosting controller 1.4.1

Exploits

source: wwwsecurityfocuscom/bid/4759/info Hosting Controller is an application which consolidates all hosting tasks into one interface Hosting Controller runs on Microsoft Windows operating systems The DSNManager script does not sufficiently filter dot-dot-slash (/) sequences from URL parameters, making it prone to directory traversa ...