Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2845▼ 222 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.8%—Hosting Controller31/10/200616/6/2026
Hosting Controller 6.1 versiones anteriores a Hotfix 3.3 permite a atacantes remotos (1) borrar el directorio virtual de un sitio de su elección mediante el párametro modificado ForumID en una acción "deshabilita foro" en DisableForum.asp y (2) crear un directorio virtual de foro de su elección mediante un paráemtro…
ModificadaAlta (7.5)3.2%💥 ExploitHosting Controller31/10/200616/6/2026
Multiples vulnerabilidades de inyección de SQL en el Hosting Controller 6.1 anterior al Hotfix 3.3 permite a atacantes remotos la ejecución de comandos SQL a través del parámetro ForumID en el (1) DisableForum.asp y (2) enableForum.asp. NOTE: se reportó posteriormente que la vulnerabilidad está presente en el Hotfix…
ModificadaMedia (6.5)2.7%💥 ExploitHosting Controller22/6/200616/6/2026
Vulnerabilidad no especificada en Hosting Controller antes de la versión v6.1 (alias Hotfix v3.2) permite, a atacantes remotos autenticados, obtener privilegios de administrador, listar todos los distribuidores, o cambiar las contraseñas de distribuidores a través de vectores no especificados. NOTA: debido a la falta…
ModificadaMedia (4.3)1.9%💥 ExploitVirtual Hosting Control System4/5/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, or (3) year parameter.
ModificadaAlta (7.5)2.8%—Cisco User Registration ToolCisco Wireless LAN Solution EngineCiscoworks 2000 Service Management SolutionCisco Hosting Solution Engine+121/4/200616/6/2026
Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell…
ModificadaAlta (7.8)1.6%—Hosting Controller13/4/200616/6/2026
Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials. NOTE: the provenance of this information is unknown; the details are obtained from third party…
ModificadaMedia (5)2.2%—Hosting Controller5/4/200616/6/2026
admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3…
ModificadaMedia (4)1.3%—Hosting Controller5/4/200616/6/2026
Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary files via an absolute path in the OpenPath parameter.
ModificadaMedia (5.8)2.5%💥 ExploitWebhost Automation Helm WEB Hosting Control Panel28/3/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp.
ModificadaAlta (7.5)1.9%—Hosting Controller14/3/200616/6/2026
SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaAlta (7.5)3.1%💥 ExploitVirtual Hosting Control System15/2/200616/6/2026
change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access.
ModificadaAlta (10)2.9%—Virtual Hosting Control System15/2/200616/6/2026
add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access.
ModificadaMedia (4.3)1.3%—Virtual Hosting Control System15/2/200616/6/2026
Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the…
ModificadaAlta (10)5.2%💥 ExploitVirtual Hosting Control System15/2/200616/6/2026
The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access.
ModificadaMedia (6.5)1.8%—Hosting Controller8/2/200616/6/2026
Vulnerabilidad de inyección de SQL en Hosting Controller 6.1 Hotfix 2.8 permite a usuarios remotos autenticados ejecutar órdenes SQL de su elección mediante el parámetro (1) GatewayID en una acción añadir en AddGatewaySettings.asp y (2) el parámetro IP en IPManager.asp.
ModificadaMedia (4.3)1.9%💥 ExploitHelm Hosting Control Panel14/1/200616/6/2026
Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.
ModificadaMedia (4.3)1.2%—Zaygo Hostingcart16/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to zaygo.cgi.
ModificadaMedia (4.3)2.2%💥 ExploitVirtual Hosting Control System29/11/200516/6/2026
Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script.
AnalizadaAlta (7.5)4.1%💥 ExploitSoftbizscripts WEB Hosting Directory Script26/11/200516/6/2026
Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an…
ModificadaMedia (5)1.4%—Hosting Controller22/9/200516/6/2026
Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability."
ModificadaMedia (4.6)1.9%💥 ExploitHosting Controller12/7/200516/6/2026
Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action.
ModificadaMedia (4.3)3.6%💥 ExploitHosting Controller29/6/200516/6/2026
Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter.
ModificadaAlta (7.5)2.1%💥 ExploitHosting Controller1/6/200516/6/2026
SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter.
ModificadaMedia (5)83%💥 ExploitCisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+7231/5/200516/6/2026
Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old.
ModificadaAlta (7.5)5.6%💥 ExploitHosting Controller27/5/200516/6/2026
Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp.