H-Sphere Webshell Command2.CC...

- AV AC AU C I A
发布: 2003-01-06
修订: 2025-04-13

The H-Sphere Webshell component is prone to a remote command execution vulnerability. This issue exists in the 'command2.CC' source file and is due to insufficient validation of input supplied via the 'zipfile' URI parameter. It is possible for a remote attacker to supply shell commands via this URI parameter, which will be executed with the privileges of Webshell. It should be noted that this issue was discovered in H-Sphere 2.3 RC3. It is not yet known whether earlier versions are also vulnerable.

0%
暂无可用Exp或PoC
当前有0条受影响产品信息