Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unauthorized actions as an administrator, including file deletion and creation, via a link or IMG tag to the (1) overkill, (2) futils, or (3) edit actions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
positive_software h-sphere WebShell 'actions.php' 跨站请求伪造漏洞
Vulnerability Description
Positive Software H-Sphere WebShell的actions.php中存在跨站请求伪造漏洞,远程攻击者可以通过对overkill,futils,或edit操作的一个链接或IMG标签来执行未授权操作,可以像管理员一样删除和创建文件。
CVSS Information
N/A
Vulnerability Type
N/A