Description
|
|
Two vulnerabilities were identified in Hosting Controller, which could be exploited by remote attackers to execute arbitrary SQL commands. These flaws are due to input validation errors in the "/AdminSettings/IPManager.asp" and "/AdminSettings/AddGatewaySettings.asp" scripts that do not properly validate the "IP" and "GatewayID" parameters before being used in SQL statements, which could be exploited by malicious people to conduct SQL injection attacks.
|