First published: Fri Jan 13 2006(Updated: )
Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 Patch 8 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter in a login action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Positive Software H-Sphere Winbox | =2.4.1 | |
Positive Software H-Sphere Winbox | =2.4.1_patch_1 | |
Positive Software H-Sphere Winbox | =2.4.1_patch_2 | |
Positive Software H-Sphere Winbox | =2.4.1_patch_3 | |
Positive Software H-Sphere Winbox | =2.4.1_patch_4 | |
Positive Software H-Sphere Winbox | =2.4.1_patch_5 | |
Positive Software H-Sphere Winbox | =2.4.1_patch_6 | |
Positive Software H-Sphere Winbox | =2.4.1_patch_7 | |
Positive Software H-Sphere Winbox | =2.4.2 | |
Positive Software H-Sphere Winbox | =2.4.2_beta_1 | |
Positive Software H-Sphere Winbox | =2.4.2_beta_2 | |
Positive Software H-Sphere Winbox | =2.4.2_beta_3 | |
Positive Software H-Sphere Winbox | =2.4.2_patch_1 | |
Positive Software H-Sphere Winbox | =2.4.2_patch_2 | |
Positive Software H-Sphere Winbox | =2.4.2_patch_3 | |
Positive Software H-Sphere Winbox | =2.4.2_patch_4 | |
Positive Software H-Sphere Winbox | =2.4.2_patch_5 | |
Positive Software H-Sphere Winbox | =2.4.2_rc1 | |
Positive Software H-Sphere Winbox | =2.4.2_rc2 | |
Positive Software H-Sphere Winbox | =2.4.3 | |
Positive Software H-Sphere Winbox | =2.4.3_beta_1 | |
Positive Software H-Sphere Winbox | =2.4.3_beta_2 | |
Positive Software H-Sphere Winbox | =2.4.3_patch_1 | |
Positive Software H-Sphere Winbox | =2.4.3_patch_2 | |
Positive Software H-Sphere Winbox | =2.4.3_patch_3 | |
Positive Software H-Sphere Winbox | =2.4.3_patch_4 | |
Positive Software H-Sphere Winbox | =2.4.3_patch_5 | |
Positive Software H-Sphere Winbox | =2.4.3_patch_6 | |
Positive Software H-Sphere Winbox | =2.4.3_patch_7 | |
Positive Software H-Sphere Winbox | =2.4.3_patch_8 | |
Positive Software H-Sphere Winbox | =2.4.3_rc1 | |
Positive Software H-Sphere Winbox | =2.4.3_rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0193 has a moderate severity rating due to its potential for cross-site scripting attacks.
To fix CVE-2006-0193, update Positive Software H-Sphere to version 2.4.3 Patch 9 or later.
Exploitation of CVE-2006-0193 may result in unwanted redirections or unauthorized content displayed to users.
CVE-2006-0193 affects Positive Software H-Sphere versions 2.4.3 Patch 8 and earlier.
Anyone using the vulnerable versions of Positive Software H-Sphere could be at risk of cross-site scripting attacks.