CVE-2006-1620

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/04/2006
Last modified:
03/04/2025

Description

admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:hosting_controller:hosting_controller:*:*:*:*:*:*:*:* 6.1_hotfix_3.3 (including)
cpe:2.3:a:hosting_controller:hosting_controller:2002_rc_1:*:*:*:*:*:*:*