Positive Software

    Dashboard / Vendors

    Products: 4
    Vulnerabilities: 12
    Known Exploited: 0
    2
    Critical Level Threats
    3
    High Level Threats
    6
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2008-4448

    Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unauthorized actions as an administrator, including file deletion and creation, via a link or IMG tag to the (1) overkill, (2) futils, or (3) edit actions.

    Last Modified: Apr 23, 2026
    Published: Oct 06, 2008

    CVE-2008-4447

    Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn parameter during a dload action, (2) the mask parameter during a search action, and (3) the tab parameter during a sysinfo action.

    Last Modified: Apr 23, 2026
    Published: Oct 06, 2008

    CVE-2008-1049

    Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and 2.5 before Patch 11, has unknown impact and attack vectors.

    Last Modified: Apr 23, 2026
    Published: Feb 27, 2008

    CVE-2007-2633

    Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files via a .. (dot dot) in the template parameter.

    Last Modified: Apr 23, 2026
    Published: May 13, 2007

    CVE-2006-6382

    The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which allows local users to append log data to arbitrary files via a symlink attack. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

    Last Modified: Apr 23, 2026
    Published: Dec 07, 2006
    Items Per Page
    Positive_Software Vulnerabilities & Security CVEs | CVE-DB