exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

hcXSS.txt

hcXSS.txt
Posted Dec 26, 2005
Authored by Lone Rider Knight

Hosting Controller is susceptible to cross site scripting attacks.

tags | exploit, xss
SHA-256 | 9177f651653cd03b8f7050039aa7280d2dcd1416da8d49e0127f4f47d917a413

hcXSS.txt

Change Mirror Download
                            In GOD We Trust
Kachal667 Under9round Team (KuT)
Hi,
Here's my(LrK) new advisory about Hosting Controller.

Hosting Controller - CSS vulnerabilities

Found date : Pri8
Public Date: 02/11/2005

Summary
-------

Hosting Controller is an all-in-one administrative hosting tool for Windows.
It automates a wide range of hosting tasks and provides control of each
hosted site to the respective owners. Hosting
Controller is now widely
used by
hosting providers and can be found at
http://www.hostingcontroller.com.

HostingController was
tested. (Probably all prior versions)

Vulnerability


Impact: An attacker may be able to put him message or photo or ..
not intended to
be publically accessible and upload scripts to
manipulate files and
control administration of sites using the latest
version of HostingController.

Lone Rider Knight


Details
-------

Vulnerability


Hosting Controller has a security flaw which allows
outside attackers
to Put her message with css

Sample scripts that allow browsing anywhere on the
server:
http://www.eg.com/admin/hosting/error.asp?error=<salam!>
http://www.eg.com/admin/hosting/error.asp?error=<IMG%20height=340%20src="http://eg.com/Deface/deface.jpg"%20width="596">
http://www.eg.com/hosting/error.asp?error=<IMG%20height=340%20src="http://eg.com/Deface/deface.jpg"%20width="596">

The directory "hc" is an example of the path to the
HostingController
script on the sample domain. The actual "hc" directory
name -- such as
"admin" or "hostingcontroller" -- must be discovered
for each "eg.com"
and
replaced in the above URL scripts.

Lone Rider Knight



Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close