CVE-2006-5629
Hosting Controller < 6.1 Hotfix 3.3 - SQL Injection via ForumID Parameter
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-5629. PoCs published by BugReport.IR, Soroush Dalili.
AI-analyzed exploit summary The exploit demonstrates multiple vulnerabilities in Hosting Controller 6.1 Hot fix <= 3.3, including authentication bypass, privilege escalation, and arbitrary file upload leading to remote code execution. It provides detailed steps and HTML/JS PoC code for exploiting these flaws.
Description
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.
Exploits (2)
The exploit demonstrates multiple vulnerabilities in Hosting Controller 6.1 Hot fix <= 3.3, including authentication bypass, privilege escalation, and arbitrary file upload leading to remote code execution. It provides detailed steps and HTML/JS PoC code for exploiting these flaws.
This exploit demonstrates SQL injection and command injection vulnerabilities in Hosting Controller 6.1 Hotfix <= 3.2. It allows unauthenticated users to delete virtual directories, create forum directories, and disable/enable forums via SQL injection.