4.6
CVSSv2

CVE-2005-2219

Published: 12/07/2005 Updated: 05/09/2008
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.

Vulnerable Product Search on Vulmon Subscribe to Product

hosting controller hosting controller 6.1_hotfix_2.1

Exploits

Hi, I'm Soroush Dalili from GSG (GrayHatz Security Group) Title: Hosting controller program have a security bug in "AccountActionsasp" that an authenticated user can change his/her credit and buy some services! Version: 61 HotFix 21 and older Developer url: hostingcontrollercom Comment: Hosting Controller is an application to manage a host ...