7.5
CVSSv2

CVE-2006-5629

Published: 31/10/2006 Updated: 17/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote malicious users to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and previous versions.

Vulnerable Product Search on Vulmon Subscribe to Product

hosting controller hosting controller

hosting controller hosting controller 6.1_hotfix_2.4

hosting controller hosting controller 6.1_hotfix_3.1

hosting controller hosting controller 6.1_hotfix_2.2

hosting controller hosting controller 6.1_hotfix_2.3

hosting controller hosting controller 1.1

hosting controller hosting controller 1.3

hosting controller hosting controller 6.1_hotfix_1.7

hosting controller hosting controller 6.1_hotfix_1.9

hosting controller hosting controller 6.1

hosting controller hosting controller 6.1_hotfix_1.4

hosting controller hosting controller 1.4

hosting controller hosting controller 1.4.1

hosting controller hosting controller 1.4b

hosting controller hosting controller 6.1_hotfix_2.0

hosting controller hosting controller 6.1_hotfix_2.1

hosting controller hosting controller 2002

hosting controller hosting controller 2002_rc_1

Exploits

Hosting Controller 61 Hotfix <= 32 Multi Vuln SQL_Injection, Command Injection ------- [KAPDA::59] - Hosting Controller 61 Hotfix <= 32 Vendor: Hosting Controller Vendor URL: wwwhostingcontrollercom Solution: Hotfix 33 Found Date: 7/1/2006 Release Date: 10/10/2006 Discussion: -------------------- UnAuthenticated user can 1- delete ...