First published: Mon Oct 06 2008(Updated: )
Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unauthorized actions as an administrator, including file deletion and creation, via a link or IMG tag to the (1) overkill, (2) futils, or (3) edit actions.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Positive Software H-Sphere Winbox | =4.3.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2008-4448 is considered a high severity vulnerability due to its potential for unauthorized administrative actions.
To fix CVE-2008-4448, update Positive Software H-Sphere to the latest version available from the vendor.
CVE-2008-4448 allows attackers to perform unauthorized actions as an administrator, including file deletion and creation.
CVE-2008-4448 is a Cross-Site Request Forgery (CSRF) vulnerability that can be exploited through specially crafted links or IMG tags.
CVE-2008-4448 affects Positive Software H-Sphere version 4.3.10.