Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL content type in CGI::readFile, (2) a long path in diskusage, and (3) a long fname in flist.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.384
EPSS Ranking 97.0%