CVE-2006-3147 EXPLOIT
6.5
MEDIUM · CVSS 2.0 · EPSS 2.7% (pctl 85)
Patch early
A public exploit exists.
Description
Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resellers, or change resellers' passwords via unspecified vectors. NOTE: due to the lack of precise details, it is not clear whether this is related to a previously disclosed issue such as CVE-2005-1788.
Scoring
| CVSS | 6.5 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
| EPSS | 2.68% — more likely to be exploited than 85% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-06-22 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| hosting controller | hosting controller |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Hosting Controller 6.1 Hotfix 3.1 - Privilege Escalation | 2006-07-06 |
References
- http://hostingcontroller.com/english/logs/hotfixlogv61_3_2.html
- http://secunia.com/advisories/20743
- http://securitytracker.com/id?1016444
- http://www.osvdb.org/26693
- http://www.securityfocus.com/bid/18565
- http://www.vupen.com/english/advisories/2006/2459
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27340
- http://hostingcontroller.com/english/logs/hotfixlogv61_3_2.html
- http://secunia.com/advisories/20743
- http://securitytracker.com/id?1016444
- http://www.osvdb.org/26693
- http://www.securityfocus.com/bid/18565
- http://www.vupen.com/english/advisories/2006/2459
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27340
→ the Explorer · watch your stack · NVD