PT-2003-2192 · H Sphere · H-Sphere Webshell

Published

2003-12-31

·

Updated

2008-09-05

·

CVE-2003-1247

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions H-Sphere WebShell version 2.3
Description The issue is related to multiple buffer overflows that allow remote attackers to execute arbitrary code. This can be achieved through a long URL content type in CGI::readFile(), a long path in diskusage, or a long fname in flist.
Recommendations For H-Sphere WebShell version 2.3, consider disabling the CGI::readFile(), diskusage, and flist functions until a patch is available to prevent exploitation. Restrict access to these components to minimize the risk of arbitrary code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1247

Affected Products

H-Sphere Webshell