Known Vulnerabilities for products from Positive Software
Listed below are 12 of the newest known vulnerabilities associated with the vendor "Positive Software".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-49842 json | Not Provided | 2026-06-09 | 2026-06-09 | |
| CVE-2008-4448 json | Cross-site request forgery (CSRF) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote at... | Not Provided | 2008-10-06 | 2026-04-23 |
| CVE-2008-4447 json | Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote attackers... | Not Provided | 2008-10-06 | 2026-04-23 |
| CVE-2008-1049 json | Unspecified vulnerability in Parallels SiteStudio before 1.7.2, and 1.8.x before 1.8b, as used in Parallels H-Sphere 3.0 befo... | Not Provided | 2008-02-27 | 2026-04-23 |
| CVE-2007-2633 json | Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitra... | Not Provided | 2007-05-13 | 2026-04-23 |
| CVE-2006-6382 json | The control panel for Positive Software H-Sphere before 2.5.0 RC3 creates log files in a user's directory with insecure permi... | Not Provided | 2006-12-07 | 2026-04-23 |
| CVE-2006-3278 json | Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web... | 2.6 - LOW | 2006-06-28 | 2017-07-20 |
| CVE-2006-0193 json | Cross-site scripting (XSS) vulnerability in the Hosting Control Panel (psoft.hsphere.CP) in Positive Software H-Sphere 2.4.3 ... | Not Provided | 2006-01-13 | 2025-04-03 |
| CVE-2005-4261 json | Unspecified vulnerability in Positive Software Corporation CP+ (cpplus) before 2.5.5 allows attackers to have unknown impact ... | Not Provided | 2005-12-15 | 2025-04-03 |
| CVE-2005-1606 json | H-Sphere Winbox 2.4.2 and 2.4.3 RC1 stores sensitive information such as username and password in plaintext in world-readable... | Not Provided | 2005-05-16 | 2025-04-03 |
| CVE-2005-1605 json | Cross-site scripting (XSS) vulnerability in the guestbook for SiteStudio 1.6 allows remote attackers to inject arbitrary web ... | Not Provided | 2005-05-16 | 2025-04-03 |
| CVE-2003-1248 json | H-Sphere WebShell 2.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) mode and (2) ... | Not Provided | 2003-12-31 | 2025-04-03 |
| CVE-2003-1247 json | Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL conten... | Not Provided | 2003-12-31 | 2025-04-03 |