← back
CVE-2007-6497

CVE-2007-6497

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 3.0%
exploitation probability
3.0%top 14% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a request to Hosting/Addreseller.asp with modified loginname and email parameters; and (2) allows remote authenticated users to change a credit amount and increase a discount via an UpdateUser action to Accounts/AccountActions.asp with modified UserName, FullName, CreditLimit, and DefaultDiscount parameters, a related issue to CVE-2005-2219.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.