Record summary

CVE-2004-1217 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit.

Description

Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

Proofs of concept

1

Catalogued exploits

ExploitDBHosting Controller 0.6.1 Hotfix 1.4 - Directory BrowsingExploitDB exploitby MouseNot analyzed1 file
ExploitDB

PoC details

References

4