Lucene search

K
cve[email protected]CVE-2005-1784
HistoryOct 03, 2022 - 4:22 p.m.

CVE-2005-1784

2022-10-0316:22:42
web.nvd.nist.gov
26
cve-2005-1784
hosting controller
hotfix
remote attackers
passwords
privileges
userprofile.asp
nvd

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.5%

Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.

Affected configurations

NVD
Node
hosting_controllerhosting_controllerRange6.1_hotfix_2.0

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

6.9 Medium

AI Score

Confidence

Low

0.016 Low

EPSS

Percentile

87.5%

Related for CVE-2005-1784