Directory traversal vulnerability in filemanager.asp for Hosting Controller 1.4.1 and earlier allows remote attackers to read and modify arbitrary files, and execute commands, via a .. (dot dot) in the OpenPath parameter.
| Software | From | Fixed in |
|---|---|---|
| hosting_controller / hosting_controller | 1.4.1 | 1.4.1.x |
| hosting_controller / hosting_controller | 1.4 | 1.4.x |