CVE Database
/

CVE-2006-1620

Back to search

CVE-2006-1620

Published: Apr 5, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.

VendorProductVersions

n/a

n/a

affected
n/a

References

28973
third-party-advisory
x_refsource_SECUNIA
4730
exploit
x_refsource_EXPLOIT-DB
26862
vdb-entry
x_refsource_BID
24773
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now