CVE-2007-6494
HIGH 10.0EPSS 11.8%
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction and ChangeSkin parameters.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 11.77% chance of exploitation in the next 30 days, 96th percentile
- Published
- 2007-12-20
- Updated
- 2024-08-07