Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2845▼ 222 respecto a la semana anterior
Críticas / altas1330▼ 168 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.8% | — | Hosting Controller | 31/10/2006 | 16/6/2026 | Hosting Controller 6.1 versiones anteriores a Hotfix 3.3 permite a atacantes remotos (1) borrar el directorio virtual de un sitio de su elección mediante el párametro modificado ForumID en una acción "deshabilita foro" en DisableForum.asp y (2) crear un directorio virtual de foro de su elección mediante un paráemtro… | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Hosting Controller | 31/10/2006 | 16/6/2026 | Multiples vulnerabilidades de inyección de SQL en el Hosting Controller 6.1 anterior al Hotfix 3.3 permite a atacantes remotos la ejecución de comandos SQL a través del parámetro ForumID en el (1) DisableForum.asp y (2) enableForum.asp. NOTE: se reportó posteriormente que la vulnerabilidad está presente en el Hotfix… | |
| Modificada | Media (6.5) | 2.7% | 💥 Exploit | Hosting Controller | 22/6/2006 | 16/6/2026 | Vulnerabilidad no especificada en Hosting Controller antes de la versión v6.1 (alias Hotfix v3.2) permite, a atacantes remotos autenticados, obtener privilegios de administrador, listar todos los distribuidores, o cambiar las contraseñas de distribuidores a través de vectores no especificados. NOTA: debido a la falta… | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Virtual Hosting Control System | 4/5/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, or (3) year parameter. | |
| Modificada | Alta (7.5) | 2.8% | — | Cisco User Registration ToolCisco Wireless LAN Solution EngineCiscoworks 2000 Service Management SolutionCisco Hosting Solution Engine+1 | 21/4/2006 | 16/6/2026 | Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13, Hosting Solution Engine (HSE) and User Registration Tool (URT) before 20060419, and all versions of Ethernet Subscriber Solution Engine (ESSE) and CiscoWorks2000 Service Management Solution (SMS) allow local users to gain Linux shell… | |
| Modificada | Alta (7.8) | 1.6% | — | Hosting Controller | 13/4/2006 | 16/6/2026 | Hosting Controller 6.1 stores forum/db/forum.mdb under the web document root with insufficient access control, which allows remote attackers to obtain sensitive information such as user name and password credentials. NOTE: the provenance of this information is unknown; the details are obtained from third party… | |
| Modificada | Media (5) | 2.2% | — | Hosting Controller | 5/4/2006 | 16/6/2026 | admin/accounts/AccountActions.asp in Hosting Controller 2002 RC 1 allows remote attackers to modify passwords of other users, probably via an "Update User" ActionType with a modified UserName parameter and the PassCheck parameter set to TRUE. It was later reported that the vulnerability is present in 6.1 Hotfix 3.3… | |
| Modificada | Media (4) | 1.3% | — | Hosting Controller | 5/4/2006 | 16/6/2026 | Directory traversal vulnerability in admin/folders/saveuploadfiles.asp in Hosting Controller 2002 RC 1 allows remote authenticated users to overwrite arbitrary files via an absolute path in the OpenPath parameter. | |
| Modificada | Media (5.8) | 2.5% | 💥 Exploit | Webhost Automation Helm WEB Hosting Control Panel | 28/3/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Helm Web Hosting Control Panel 3.2.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) txtDomainName parameter to domains.asp or (2) SearchText or (3) UserLevel parameters to default.asp. | |
| Modificada | Alta (7.5) | 1.9% | — | Hosting Controller | 14/3/2006 | 16/6/2026 | SQL injection vulnerability in search.asp in Hosting Controller 6.1 (Hotfix 2.9) allows remote attackers to execute arbitrary SQL commands via the search parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Virtual Hosting Control System | 15/2/2006 | 16/6/2026 | change_password.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not verify the old password when a user changes the password, which may allow remote attackers to gain unauthorized access. | |
| Modificada | Alta (10) | 2.9% | — | Virtual Hosting Control System | 15/2/2006 | 16/6/2026 | add_user.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not check user privileges when adding a new administrative user, which allows remote attackers to gain unauthorized access. | |
| Modificada | Media (4.3) | 1.3% | — | Virtual Hosting Control System | 15/2/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the… | |
| Modificada | Alta (10) | 5.2% | 💥 Exploit | Virtual Hosting Control System | 15/2/2006 | 16/6/2026 | The check_login function in login.php in Virtual Hosting Control System (VHCS) 2.4.7.1 and earlier does not exit when authentication fails, which allows remote attackers to gain unauthorized access. | |
| Modificada | Media (6.5) | 1.8% | — | Hosting Controller | 8/2/2006 | 16/6/2026 | Vulnerabilidad de inyección de SQL en Hosting Controller 6.1 Hotfix 2.8 permite a usuarios remotos autenticados ejecutar órdenes SQL de su elección mediante el parámetro (1) GatewayID en una acción añadir en AddGatewaySettings.asp y (2) el parámetro IP en IPManager.asp. | |
| Modificada | Media (4.3) | 1.9% | 💥 Exploit | Helm Hosting Control Panel | 14/1/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter. | |
| Modificada | Media (4.3) | 1.2% | — | Zaygo Hostingcart | 16/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Zaygo HostingCart 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via certain search module parameters, possibly the root parameter to zaygo.cgi. | |
| Modificada | Media (4.3) | 2.2% | 💥 Exploit | Virtual Hosting Control System | 29/11/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in gui/errordocs/index.php in Virtual Hosting Control System (VHCS) 2.2.0 through 2.4.6.2 allows remote attackers to inject arbitrary web script or HTML via query strings that are included in an error message, as demonstrated using a parameter containing script. | |
| Analizada | Alta (7.5) | 4.1% | 💥 Exploit | Softbizscripts WEB Hosting Directory Script | 26/11/2005 | 16/6/2026 | Multiple SQL injection vulnerabilities in Softbiz Web Host Directory Script 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cid parameter in search_result.php, (2) sbres_id parameter in review.php, (3) cid parameter in browsecats.php, (4) h_id parameter in email.php, and (5) an… | |
| Modificada | Media (5) | 1.4% | — | Hosting Controller | 22/9/2005 | 16/6/2026 | Unspecified vulnerability in Hosting Controller 6.1 before Hotfix 2.4 allows remote attackers to list and read contents of arbitrary drives, related to "the PHP vulnerability." | |
| Modificada | Media (4.6) | 1.9% | 💥 Exploit | Hosting Controller | 12/7/2005 | 16/6/2026 | Hosting Controller 6.1 Hotfix 2.1 allows remote authenticated users to perform unauthorized actions, such as modifying the credit limit, via a direct request to AccountActions.asp and modifying the CreditLimit parameter in an UpdateCreditLimit action. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Hosting Controller | 29/6/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in error.asp for Hosting Controller allows remote attackers to inject arbitrary web script or HTML via the error parameter. | |
| Modificada | Alta (7.5) | 2.1% | 💥 Exploit | Hosting Controller | 1/6/2005 | 16/6/2026 | SQL injection vulnerability in resellerresources.asp in Hosting Controller 6.1 Hotfix 2.0 allows remote attackers to execute arbitrary SQL commands via the jresourceid parameter. | |
| Modificada | Media (5) | 83% | 💥 Exploit | Cisco Agent DesktopCisco E-mail ManagerCisco Emergency ResponderCisco Intelligent Contact Manager+72 | 31/5/2005 | 16/6/2026 | Multiple TCP implementations with Protection Against Wrapped Sequence Numbers (PAWS) with the timestamps option enabled allow remote attackers to cause a denial of service (connection loss) via a spoofed packet with a large timer value, which causes the host to discard later packets because they appear to be too old. | |
| Modificada | Alta (7.5) | 5.6% | 💥 Exploit | Hosting Controller | 27/5/2005 | 16/6/2026 | Hosting Controller 6.1 HotFix 2.0 and earlier allows remote attackers to steal passwords and gain privileges via a modified emailaddress parameter in an updateprofile action for UserProfile.asp. |