H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request.
Affected Software
Name |
Vendor |
Start Version |
End Version |
H-sphere |
Positive_software |
2.3_rc3 (including) |
2.3_rc3 (including) |
References