CVE-2005-1654
Hosting Controller < 6.1 Hotfix 1.9 - Unauthenticated Arbitrary User Registration via Direct Request
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-1654. PoCs published by Silentium, Mouse.
AI-analyzed exploit summary This exploit targets Hosting Controller <= v6.1 by sending a crafted POST request to either the web server or hosting controller daemon to create a new user with specified credentials. It leverages an unauthenticated user registration vulnerability.
Description
Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
Exploits (2)
This exploit targets Hosting Controller <= v6.1 by sending a crafted POST request to either the web server or hosting controller daemon to create a new user with specified credentials. It leverages an unauthenticated user registration vulnerability.
This exploit demonstrates an unauthenticated user registration vulnerability in Hosting Controller. It allows an attacker to create a user and host on the target system by sending a crafted POST request to the vulnerable endpoint.