20041205 Hosting Controllermailing list
http://marc.info/?l=bugtraq&m=110237762807764&w=2 CVE-2004-1217
Hosting Controller 0.6.1 Hotfix 1.4 - Directory Browsing
Record summary
CVE-2004-1217 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.
Description
Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBHosting Controller 0.6.1 Hotfix 1.4 - Directory BrowsingExploitDB exploitby MouseNot analyzed1 file
References
411822vdb entry
http://www.securityfocus.com/bid/11822 hosting-controller-view-files(18363)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/18363 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-1217