Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2008-6465

EPSS 1.34% · P80
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2008-6465

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Multiple cross-site scripting (XSS) vulnerabilities in login.php in webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remote attackers to inject arbitrary web script or HTML via the (1) err, (2) errorcode, and (3) login parameters.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Parallels H-Sphere 脚本login.php 跨站脚本攻击漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
H-Sphere是一个主机托管服务网站自动化控制程序,一个可扩展的多服务器虚拟主机的解决方案。目前可用于Linux,Unix和Windows环境和MySQL,PostgreSQL和Microsoft SQL Server数据库等数据库环境。 Parallels H-Sphere 3.0.0 P9版本和3.1 P1版本的webshell4中的login.php存在多个跨站脚本攻击漏洞。远程攻击者可以借助(1)err,(2)错误代码和(3)登陆参数,注入任意web脚本或HTML。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2008-6465

#POC DescriptionSource LinkShenlong Link
1Parallels H-Sphere 3.0.0 P9 and 3.1 P1 contains multiple cross-site scripting vulnerabilities in login.php in webshell4. An attacker can inject arbitrary web script or HTML via the err, errorcode, and login parameters, thus allowing theft of cookie-based authentication credentials and launch of other attacks. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2008/CVE-2008-6465.yamlPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2008-6465

登录查看更多情报信息。

Same Patch Batch · n/a · 2009-03-13 · 21 CVEs total

CVE-2008-6461TYPO3 ste_prayer2扩展功能SQL注入漏洞
CVE-2008-6471mountaingrafix easylink 'detail.php' SQL注入漏洞
CVE-2008-6470ClanSphere 多个信息泄露漏洞
CVE-2008-6469Plaincart 'index.php' SQL注入漏洞
CVE-2008-6468Dieselscripts Diesel Pay 'index.php' SQL注入漏洞
CVE-2008-6467Dieselscripts Diesel Job Site 'job-info.php' SQL注入漏洞
CVE-2008-6466Akira Powered Image Gallery 'function.php' SQL注入漏洞
CVE-2008-6464Mevin Productions Basic PHP Events Lister 脚本event.php SQL注入漏洞
CVE-2008-6463TYPO3 pd_churchsearch扩展功能SQL注入漏洞
CVE-2008-6462TYPO3 myquizpoll扩展功能SQL注入漏洞
CVE-2008-6451jPORTAL 'humor.php' SQL注入漏洞
CVE-2008-6460TYPO3 mw_random_objects扩展功能SQL注入漏洞
CVE-2008-6459TYPO3 autobeuser扩展功能 SQL注入漏洞
CVE-2008-6458TYPO3 tdmaddredit扩展功能 SQL注入漏洞
CVE-2008-6457TYPO3 cgswigmore扩展功能SQL注入漏洞
CVE-2008-6456TYPO3 h_book扩展功能SQL注入漏洞
CVE-2008-6455edikon phpshop 未明向量会话劫持漏洞
CVE-2008-64546rbScript 'section.php' SQL注入漏洞
CVE-2008-64536rbScript 'section.php' 本地文件包含漏洞
CVE-2008-6452Oceandir 'show_vote.php' SQL注入漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2008-6465

No comments yet


Leave a comment