CVE-2003-1247

H-Sphere WebShell 2.3 - Remote Code Execution via Buffer Overflow in CGI::readFile diskusage and flist

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2003-1247. PoCs published by Carl Livitt.

AI-analyzed exploit summary This exploit targets a stack-based buffer overflow in H-Sphere Webshell's CGI.C component, allowing remote code execution via a crafted HTTP request. It binds a root shell to a specified port by leveraging predictable return addresses and environment variables.

Description

Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Carl Livitt · cremotelinux
https://www.exploit-db.com/exploits/22129

This exploit targets a stack-based buffer overflow in H-Sphere Webshell's CGI.C component, allowing remote code execution via a crafted HTTP request. It binds a root shell to a specified port by leveraging predictable return addresses and environment variables.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: H-Sphere Webshell 2.4 (possibly other versions)
No auth needed
Prerequisites: Network access to the target Webshell CGI · Webshell installed with SUID/GUID root
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Carl Livitt · clocallinux
https://www.exploit-db.com/exploits/22128

This exploit targets a stack-based buffer overflow in H-Sphere Webshell 2.4 (CVE-2003-1247) via a maliciously crafted 'CONTENT_TYPE' environment variable. It uses a bruteforce approach to guess the return address and buffer size, ultimately executing arbitrary shellcode to spawn a root shell.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: H-Sphere Webshell 2.4
No auth needed
Prerequisites: Local access to the system · Webshell binary must be SUID root · Target architecture must be Linux x86
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (11)

Core 11
Core References
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6537
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6540
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1005893
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/7832
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/305313
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6527
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6538

Scores

EPSS 0.0995
EPSS Percentile 95.0%

Details

Status published
Products (1)
positive_software/h-sphere 2.3_rc3
Published Dec 31, 2003
Tracked Since Feb 18, 2026