A vulnerability has been discovered in H-Sphere Webshell. The problem occurs due to insufficient bounds checking on user-supplied values. The vulnerability occurs in the diskusage.cc file and can be triggered by passing the target server a value of excessive length for the 'path' variable. Successful exploitation of this issue may allow an attacker to overwrite the vulnerable functions instruction pointer to cause the server to execute attacker-supplied code.
A vulnerability has been discovered in H-Sphere Webshell. The problem occurs due to insufficient bounds checking on user-supplied values. The vulnerability occurs in the diskusage.cc file and can be triggered by passing the target server a value of excessive length for the 'path' variable. Successful exploitation of this issue may allow an attacker to overwrite the vulnerable functions instruction pointer to cause the server to execute attacker-supplied code.