| HostMan.biz - WebSite Hosting Directory - Web Host Reviews - Hosting Companies - Web Hosts Plans | |||
| WebSite Hosting | UK Hosting | Best Hosting | Web Design | Dedicated Servers | Web Hosting Canada | Business Address | Webmaster | |||
![]() | |||
|
| |||
| HostMan.biz - news | |||
|
Secunia Reports Flaws in Hosting Controller.
2005-07-18, HostMan.biz According to security organization Secunia (secunia.org), flaws in the Hosting Controller (hostingcontroller.com) Web hosting automation solution have been discovered that could be exploited to steal or modify sensitive data or conduct SQL injection attacks. According to Secunia, the "planmanagerstep1.asp" script is not properly restricted and can be exploited by non-privileged users to add a plan to the database. The "editplanopt1.asp" has the same problem, allowing non-privileged users to change plans within the database. The "IISActions.asp" script is also not properly restricted, opening the door for non-privileged users to add domains with unlimited quota. Finally, input passed to the "hostcustid" parameter of "plandetails.asp" is not properly sanitized before being used in a SQL query. This flaw could be exploited to manipulate SQL queries through arbitrary SQL code injections. The solution, Secunia says, is to edit the source code to ensure that input is verified and sanitized properly. The flaws affect versions 6.x of Hosting Controller and are rated by Secunia as moderately critical. |
|||
|
Hosting Glossary ASP (Active Server Pages) | Auto Responder | Bandwidth | CGI, CGI-BIN | Colocation | Domain Name | E-mail | FTP | POP3 E-mail | IP Address | Name Server | Server Side Includes (SSI) | Spam (Spamming) | |
| Webmaster Resources |
| New York | Web Hosting Forums | Review Hosting | Web Hosting Blog | Web Hosting | Hosting in Europe |
| Unix Hosting | Windows Hosting | Budged Hosting | Reseller Hosting | Shared Hosting | Decicated Hosting |
|
Webmaster Resources | Contact Us |
| © HostMan.biz, Hosting Directory since 2003 |