S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 6, 2024

CVE-2008-6465 Scanner

CVE-2008-6465 scanner - Cross-Site Scripting (XSS) vulnerability in Parallels H-Sphere

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2008-6465
4.3
CVSS

Multiple cross-site scripting (XSS) vulnerabilities in login.php in webshell4 in Parallels H-Sphere 3.0.0 P9 and 3.1 P1 allow remote attackers to inject arbitrary web script or HTML via the (1) err, (2) errorcode, and (3) login parameters.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Parallels H-Sphere is a web hosting automation software that is used by businesses to manage their online resources. This powerful tool allows users to easily create, manage, and configure hosting services for websites, email, and databases. With H-Sphere, businesses can manage multiple servers from a single interface, making it a popular choice for hosting providers.

CVE-2008-6465 is a critical vulnerability that was detected in Parallels H-Sphere 3.0.0 P9 and 3.1 P1. The vulnerability is related to cross-site scripting (XSS) attacks that can be executed through login.php in webshell4. Attackers are able to inject arbitrary web script or HTML by using the err, errorcode, and login parameters.

When exploited, this vulnerability can lead to serious consequences for businesses. Attackers can gain access to sensitive information such as login credentials and other confidential data. They can also use the injected code to hijack user sessions, redirect users to malicious sites, and conduct phishing attacks. This makes it imperative for businesses to take necessary precautions to mitigate the risk of such attacks.

s4e.io, a feature-rich security platform, provides businesses with an easy and convenient way to stay informed about vulnerabilities in their digital assets. This platform offers a vast array of resources, including vulnerability scans, penetration testing, and security assessments, allowing businesses to identify and address security issues quickly and efficiently. With s4e.io, businesses can safeguard their online resources and keep their customers' data secure.

 

REFERENCES

Solution Advice

To protect against this vulnerability, the following precautions can be taken:

  • Regularly update the Parallels H-Sphere system to the latest version.
  • Restrict access to login.php and webshell4 to only authorized personnel.
  • Implement web application firewalls (WAFs) to detect and block malicious activity.
  • Conduct regular security audits and penetration testing to identify and address vulnerabilities.
  • Educate employees on how to recognize and avoid phishing emails and other suspicious activity.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2008-6465 scanner - Cross-Site Scripting (XSS) vulnerability in Parallels H-Sphere | S4E