Description
Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Carl Livitt · cremotelinux
https://www.exploit-db.com/exploits/22129
exploitdb
WORKING POC
VERIFIED
by Carl Livitt · clocallinux
https://www.exploit-db.com/exploits/22128
References (11)
Scores
EPSS
0.5293
EPSS Percentile
98.0%
Details
Status
published
Products (1)
positive_software/h-sphere
2.3_rc3
Published
Dec 31, 2003
Tracked Since
Feb 18, 2026