Positive Software's vulnerability footprint centers on a focused set of hosting-control and website-building products, including H-Sphere, SiteStudio, and control-panel offerings that serve small-to-medium web hosting and e-commerce environments. The recurring weakness classes reflect application-layer input handling and session management, dominated by cross-site scripting, cross-site request forgery, and related web-application flaws endemic to legacy hosting-panel software. Vulnerabilities affecting this vendor tend to acquire public exploit code; live severity, exploitation, and detailed exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Positive Software over time
Signals from CVEs in this vendor scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2003-1247HIGH Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, | Dec 31, 2003 | 7.5 | 32 | NO | YES |
CVE-2008-1049HIGH Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 before Patch 9 and 2.5 before Patch 11, has unknown impact | Feb 27, 2008 | 10.0 | 27 | NO | NO |
CVE-2007-2633HIGH Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files via a .. (dot dot) in the template param | May 13, 2007 | 10.0 | 25 | NO | NO |
CVE-2003-1248HIGH H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) zipfile parameters in a URL request. | Dec 31, 2003 | 7.5 | 25 | NO | NO |
CVE-2008-4447MEDIUM Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to inject arbitrary web script or HTML via (1) the fn | Oct 6, 2008 | 4.3 | 21 | NO | YES |
CVE-2005-1606MEDIUM H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable log files, which allows local users to gain privileges | May 16, 2005 | 4.6 | 21 | NO | YES |
CVE-2005-4261HIGH Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact and attack vectors, related to "a possible security fla | Dec 15, 2005 | 7.8 | 20 | NO | NO |
CVE-2008-4448MEDIUM Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers to perform unauthorized actions as an administr | Oct 6, 2008 | 6.8 | 18 | NO | NO |
CVE-2006-6382MEDIUM The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permissions, which allows local users to append log data to | Dec 7, 2006 | 6.8 | 18 | NO | NO |
CVE-2005-1605MEDIUM Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web script or HTML via the name field to (1) psoft.guestboo | May 16, 2005 | 6.8 | 18 | NO | NO |
Signals from CVEs in this vendor scope (12 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Positive Software.
Media articles that mention a CVE ID that affects a product developed by Positive Software — matched by CVE ID, not by vendor name.