CVE-2004-1217
MEDIUM 5.0EPSS 2.9%
Hosting Controller 6.1 Hotfix 1.4, and possibly other versions, allows remote attackers to view arbitrary directories by specifying the target pathname in the FilePath parameter to (1) Statsbrowse.asp or (2) Generalbrowse.asp.
- CVSS v2.0
- 5.0 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N - EPSS
- 2.91% chance of exploitation in the next 30 days, 86th percentile
- Published
- 2004-12-15
- Updated
- 2024-08-08