Exploitation Summary
EIP tracks 1 public exploit for CVE-2004-1217. PoCs published by Mouse.
AI-analyzed exploit summary This advisory describes a directory traversal vulnerability in Hosting Controller, allowing attackers to browse arbitrary files and directories on the server via manipulated URLs in Statsbrowse.asp and Generalbrowse.asp.
Description
Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.
Exploits (1)
This advisory describes a directory traversal vulnerability in Hosting Controller, allowing attackers to browse arbitrary files and directories on the server via manipulated URLs in Statsbrowse.asp and Generalbrowse.asp.