VYPR
Unrated severityNVD Advisory· Published Mar 7, 2005· Updated Apr 16, 2026

CVE-2005-0695

CVE-2005-0695

Description

The password recovery feature (forgotpassword.asp) in Hosting Controller 6.1 Hotfix 1.7 and earlier allows remote attackers to determine the owner's e-mail address by providing a portion of the domain name to the "login ID" field.

Affected products

7
  • cpe:2.3:a:hosting_controller:hosting_controller:1.1:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:hosting_controller:hosting_controller:1.1:*:*:*:*:*:*:*
    • cpe:2.3:a:hosting_controller:hosting_controller:1.3:*:*:*:*:*:*:*
    • cpe:2.3:a:hosting_controller:hosting_controller:1.4.1:*:*:*:*:*:*:*
    • cpe:2.3:a:hosting_controller:hosting_controller:1.4b:*:*:*:*:*:*:*
    • cpe:2.3:a:hosting_controller:hosting_controller:6.1:*:*:*:*:*:*:*
    • cpe:2.3:a:hosting_controller:hosting_controller:6.1_hotfix_1.4:*:*:*:*:*:*:*
    • cpe:2.3:a:hosting_controller:hosting_controller:6.1_hotfix_1.7:*:*:*:*:*:*:*

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.