Lucene search

K
prionPRIOn knowledge basePRION:CVE-2007-6495
HistoryDec 20, 2007 - 8:46 p.m.

Remote code execution

2007-12-2020:46:00
PRIOn knowledge base
www.prio-n.com
2

7.8 High

AI Score

Confidence

Low

0.023 Low

EPSS

Percentile

89.8%

inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2) www, (3) Special, and (4) log at arbitrary locations under the web root via a modified Dirroot parameter in an AddUser action to accounts/AccountActions.asp. NOTE: this can be leveraged for remote code execution by changing the permissions of \Forum\db, which is configured for execution of ASP scripts with administrative privileges, and then uploading a script to \Forum\db.

CPENameOperatorVersion
hosting_controllereq6.1.0-hotfix3.3

7.8 High

AI Score

Confidence

Low

0.023 Low

EPSS

Percentile

89.8%

Related for PRION:CVE-2007-6495