Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Hosting 控件 AccountActions.asp 权限许可和访问控制漏洞
Vulnerability Description
Hosting 控件2002 RC 1版本的admin/accounts/AccounstActions.asp文件允许远程攻击者修改其它用户的密码,方式可能是通过一个带UserName参数和设置为TRUE的PassCheck参数的"Update User"行为类型。
CVSS Information
N/A
Vulnerability Type
N/A