VulnerabilityModified
CVE-2002-0776
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.
HIGH 7.5EPSS 1.79%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.79%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.79% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- hosting controller/hosting controller
- Source
- cve@mitre.org
References
- http://hostingcontroller.com/english/logs/sp2log.htmlPatch, Vendor Advisory
- http://online.securityfocus.com/archive/1/282129Exploit, Patch, Vendor Advisory
- http://www.iss.net/security_center/static/9554.php
- http://www.securityfocus.com/bid/5229
- http://hostingcontroller.com/english/logs/sp2log.htmlPatch, Vendor Advisory
- http://online.securityfocus.com/archive/1/282129Exploit, Patch, Vendor Advisory
- http://www.iss.net/security_center/static/9554.php
- http://www.securityfocus.com/bid/5229
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.