7.5
CVSSv2

CVE-2005-1784

Published: 27/05/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Hosting Controller 6.1 HotFix 2.0 and previous versions allows remote malicious users to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.

Vulnerable Product Search on Vulmon Subscribe to Product

hosting controller hosting controller

Exploits

<!-- Hi, I'm Soroush Dalili from GSG (GrayHatz Security Group) Title: Hosting controller program have a security bug in "UserProfileasp" that an authenticated user can change other's profiles Why is it dangerous: a user can change other's email address and then use forgot password to recieve their password! also he/she can gain administrato ...