Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Directory traversal vulnerability in Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files and directories via a .. (dot dot) in arguments to (1) file_editor.asp, (2) folderactions.asp, or (3) editoractions.asp.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Hosting Controller权限检查不充分漏洞
Vulnerability Description
Hosting Controller是一款在一个接口上集中化管理所有主机任务的应用程序。Hosting Controller提供所有用户需要进行相关WEB管理的请求控制,运行在Microsoft windows操作系统下。 Hosting Controller对用户权限验证不完全可导致未授权修改目录内容。 由于Hosting Controller在当限制WEB页面的请求时,没有正确验证用户权限,攻击者可以提交包含多个'../'字符的请求给'folderactions.asp'或者'file_editor.
CVSS Information
N/A
Vulnerability Type
N/A