PT-2003-2192 · H Sphere · H-Sphere Webshell
Published
2003-12-31
·
Updated
2008-09-05
·
CVE-2003-1247
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
H-Sphere WebShell version 2.3
Description
The issue is related to multiple buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved through a long URL content type in
CGI::readFile(), a long path in diskusage, or a long fname in flist.Recommendations
For H-Sphere WebShell version 2.3, consider disabling the
CGI::readFile(), diskusage, and flist functions until a patch is available to prevent exploitation. Restrict access to these components to minimize the risk of arbitrary code execution.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
H-Sphere Webshell