Home/Product/positive software h sphere
Product

positive software h sphere

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-30777
all versions
Parallels H-Sphere 3.6.1713 allows XSS via the index_en.php from parameter.
6.1MEDIUM
CVE-2012-5004
all versions
Multiple cross-site request forgery (CSRF) vulnerabilities in Parallels H-Sphere 3.3 Patch 1 allow remote attackers to hijack the
CVE-2008-6465
all versions
Multiple cross-site scripting (XSS) vulnerabilities in login.php in webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remo
CVE-2008-4448
all versions
Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attacke
CVE-2008-4447
all versions
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to i
CVE-2008-1049
<= 2.5_patch_10
Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Pa
CVE-2006-6382
all versions
The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permission
CVE-2006-3278
<= 2.5.1_beta_1
Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web scri
CVE-2006-0193
all versions
Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch
CVE-2003-1248
all versions
H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfi
CVE-2003-1247
all versions
Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content typ
threatengine.sh