Vulnerabilities > Positive Software

DATE CVE VULNERABILITY TITLE RISK
2008-10-06 CVE-2008-4448 Cross-Site Request Forgery (CSRF) vulnerability in Positive Software H-Sphere 4.3.10
Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unauthorized actions as an administrator, including file deletion and creation, via a link or IMG tag to the (1) overkill, (2) futils, or (3) edit actions.
6.8
2008-10-06 CVE-2008-4447 Cross-Site Scripting vulnerability in Positive Software H-Sphere 4.3.10
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a dload action, (2) the mask parameter during a search action, and (3) the tab parameter during a sysinfo action.
4.3
2008-02-27 CVE-2008-1049 Unspecified vulnerability in Positive Software H-Sphere and Sitestudio
Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and 2.5 before Patch 11, has unknown impact and attack vectors.
network
low complexity
positive-software
critical
10.0
2007-05-13 CVE-2007-2633 Directory Traversal vulnerability in Positive Software Sitestudio 1.6
Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files via a ..
network
low complexity
positive-software
critical
10.0
2006-12-07 CVE-2006-6382 Unspecified vulnerability in Positive Software H-Sphere 2.4.3
The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which allows local users to append log data to arbitrary files via a symlink attack.
local
low complexity
positive-software
6.8
2006-06-28 CVE-2006-3278 Cross-Site Scripting vulnerability in H-Sphere
Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) next_template, (2) start, (3) curr_menu_id, and (4) arid parameters in psoft/servlet/resadmin/psoft.hsphere.CP when using the mailman/massmail.html template_name.
network
high complexity
positive-software
2.6
2006-01-13 CVE-2006-0193 Cross-Site Scripting vulnerability in H-Sphere
Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.
4.3
2005-12-15 CVE-2005-4261 Perl Security vulnerability in Positive Software Corporation CP+
Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectors, related to "a possible security flaw caused by a bug in Perl." NOTE: unless CP+ includes its own copy of Perl with CVE-2005-3962, this is a different vulnerability than CVE-2005-3962; however, there is insufficient information to be sure.
network
low complexity
positive-software
7.8
2005-05-16 CVE-2005-1606 Unspecified vulnerability in Positive Software H-Sphere Winbox 2.4.2Patch4/2.4.3Rc1
H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges.
local
low complexity
positive-software
4.6
2005-05-16 CVE-2005-1605 HTML Injection vulnerability in Positive Software Corporation SiteStudio
Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestbook.GuestBookServ in Standalone Site Studio or (2) E-Guest_sign.pl in Integrated Site Studio with H-Sphere.
6.8