Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a dload action, (2) the mask parameter during a search action, and (3) the tab parameter during a sysinfo action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
positive_software h-sphere WebShell 'actions.php' 跨站脚本攻击漏洞
Vulnerability Description
Positive Software H-Sphere WebShell的actions.php中存在跨站脚本攻击漏洞,远程攻击者可以通过一个dload操作中的fn参数,一个search操作中的mask参数,以及一个sysinfo操作中的tab参数,以执行任意web脚本或HTML。
CVSS Information
N/A
Vulnerability Type
N/A