Vulnerabilities > Positive Software > H Sphere > 2.4.3

DATE CVE VULNERABILITY TITLE RISK
2006-12-07 CVE-2006-6382 Unspecified vulnerability in Positive Software H-Sphere 2.4.3
The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which allows local users to append log data to arbitrary files via a symlink attack.
local
low complexity
positive-software
6.8
2006-01-13 CVE-2006-0193 Cross-Site Scripting vulnerability in H-Sphere
Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.
4.3