Title: An attacker can gain reseller privileges and after that can gain admin privileges Version: 6.1 Hotfix <= 3.1 Developer url: www.Hostingcontroller.com Solution: Update to Hotfix 3.2 Discover date: 2005,Summer Report date (to hc company): Sat Jun 10, 2006 Publish date (in security forums): Thu July 06, 2006 ------------------------------------------------------------------------------------- =============================================== 1- This code give resadmin session to a user: Bug in "hosting/addreseller.asp", No checker is available. ---------------------------------------------------