CVE-2002-0776
UnknownEPSS 1.79%
Last modified
CVE-2002-0776 is a vulnerability of currently unknown severity. getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.. EPSS estimates a 1.79% chance of exploitation in the next 30 days.
Description
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Hosting Controller | Hosting Controller | 2002 |
References
- http://hostingcontroller.com/english/logs/sp2log.htmlPatch, Vendor Advisory
- http://online.securityfocus.com/archive/1/282129Exploit, Patch, Vendor Advisory
- http://hostingcontroller.com/english/logs/sp2log.htmlPatch, Vendor Advisory
- http://online.securityfocus.com/archive/1/282129Exploit, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2002-0776?
getuserdesc.asp in Hosting Controller 2002 allows remote attackers to change the passwords of arbitrary users and gain privileges by modifying the username parameter, as addressed by the "UpdateUser" hot fix.
How severe is CVE-2002-0776?
Severity scoring for CVE-2002-0776 is pending analysis. The EPSS model estimates a 1.79% probability of exploitation in the next 30 days.
How do I fix CVE-2002-0776?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2002
- CVE-2002-0770Quake 2 (Q2) server 3.20 and 3.21 allows remote attackers to…
- CVE-2002-0771Cross-site scripting vulnerability in viewcvs.cgi for ViewCV…
- CVE-2002-0772Directory traversal vulnerability in dsnmanager.asp for Host…
- CVE-2002-0773imp_rootdir.asp for Hosting Controller allows remote attacke…
- CVE-2002-0774Hosting Controller creates a default user AdvWebadmin with a…
- CVE-2002-0775browse.asp in Hosting Controller allows remote attackers to …
- CVE-2002-0777Buffer overflow in the LDAP component of Ipswitch IMail 7.1 …
- CVE-2002-0778The default configuration of the proxy for Cisco Cache Engin…
- CVE-2002-0779FTP proxy server for Novell BorderManager 3.6 SP 1a allows r…
- CVE-2002-0780IP/IPX gateway for Novell BorderManager 3.6 SP 1a allows rem…
- CVE-2002-0781RTSP proxy for Novell BorderManager 3.6 SP 1a allows remote …
- CVE-2002-0782Novell BorderManager 3.5 with PAT (Port-Address Translate) e…
Are you affected by CVE-2002-0776?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
