EDB-4730
webappsaspVERIFIED
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6504CVE-2007-6503CVE-2007-6502+8 more
BugReport.IR12/13/2007
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/addreseller.asp with a username in the reseller parameter, followed by a request to AdminSettings/displays.asp with the DecideAction and ChangeSkin parameters.