|
H-Sphere Webshell Command.C Mode URI Parameter Command Execution Vulnerability
The H-Sphere Webshell component is prone to a remote command execution vulnerability. This issue exists in the 'command.C' source file and is due to insufficient validation of input supplied via the 'mode' URI parameter. It is possible for a remote attacker to supply shell commands via this URI parameter, which will be executed with the privileges of Webshell. It should be noted that this issue was discovered in H-Sphere 2.3 RC3. It is not yet known whether earlier versions are also vulnerable. |
|
|
Privacy Statement |