H-Sphere Webshell Command.C Mode URI Parameter Command Execution Vulnerability

The H-Sphere Webshell component is prone to a remote command execution vulnerability.

This issue exists in the 'command.C' source file and is due to insufficient validation of input supplied via the 'mode' URI parameter. It is possible for a remote attacker to supply shell commands via this URI parameter, which will be executed with the privileges of Webshell.

It should be noted that this issue was discovered in H-Sphere 2.3 RC3. It is not yet known whether earlier versions are also vulnerable.


Privacy Statement
Copyright 2010, SecurityFocus