Hosting Controller 6.1 Hotfix 1.9 and earlier allows remote attackers to register arbitrary users via a direct request to addsubsite.asp with the loginname and password parameters set.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
http://secunia.com/advisories/15271 | third party advisory broken link |
http://isun.shabgard.org/hc3.txt | exploit patch broken link |