HC6.1: Release
Notes for Post Hotfix 3.3 Security Patch
- Fixed a bug where remote attacker were changing
passwords of HC users.
- Fixed a bug where attacker were copying a file to
hosting controller /web directory to execute his commands
by taking administrative privileges.
- Fixed a bug where new user were being created remotely
by using a script.
- Fixed an issue where all databases were listed for
attacker by a SQL injection bug.
- Fixed a bug where user could change his credit
limit or increase his discount.
- Fixed a bug where User could uninstall FrontPage
extensions for all domains created on the server.
- Fixed a bug where user could delete gateway information
remotely.
- Fixed a bug where user could enable or disable payment
type remotely.
- Fixed a bug where user could see information of
all webadmins created on the server.
- Fixed a bug where user could import/edit the plans.
- Fixed a bug where remote attacker could enable or
disable forum by SQL Injection.
- Fixed a bug where user could change host headers
of all domains created on the server.
|