CVE Database
/

CVE-2007-6495

Back to search

CVE-2007-6495

Published: Dec 20, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permissions of directories named (1) db, (2) www, (3) Special, and (4) log at arbitrary locations under the web root via a modified Dirroot parameter in an AddUser action to accounts/AccountActions.asp. NOTE: this can be leveraged for remote code execution by changing the permissions of \Forum\db, which is configured for execution of ASP scripts with administrative privileges, and then uploading a script to \Forum\db.

VendorProductVersions

n/a

n/a

affected
n/a

References

44184
vdb-entry
x_refsource_OSVDB
28973
third-party-advisory
x_refsource_SECUNIA
3474
third-party-advisory
x_refsource_SREASON
4730
exploit
x_refsource_EXPLOIT-DB
26862
vdb-entry
x_refsource_BID
1019222
vdb-entry
x_refsource_SECTRACK

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now