Show filters
83 Total Results
Displaying 21-30 of 83
Sort by:
Attacker Value
Unknown
CVE-2019-16957
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows XSS via the First Name field of a User Account.
0
Attacker Value
Unknown
CVE-2019-16955
Disclosure Date: December 18, 2020 (last updated February 22, 2025)
SolarWinds Web Help Desk 12.7.0 allows XSS via an uploaded SVG document in a request.
0
Attacker Value
Unknown
CVE-2020-26546
Disclosure Date: October 12, 2020 (last updated February 22, 2025)
An issue was discovered in HelpDeskZ 1.0.2. The feature to auto-login a user, via the RememberMe functionality, is prone to SQL injection. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
0
Attacker Value
Unknown
CVE-2020-2506
Disclosure Date: October 07, 2020 (last updated February 22, 2025)
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this improper access control vulnerability could allow attackers to compromise the security of the software by gaining privileges, or reading sensitive information. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
0
Attacker Value
Unknown
CVE-2020-2507
Disclosure Date: October 07, 2020 (last updated February 22, 2025)
The vulnerability have been reported to affect earlier versions of QTS. If exploited, this command injection vulnerability could allow remote attackers to run arbitrary commands. This issue affects: QNAP Systems Inc. Helpdesk versions prior to 3.0.3.
0
Attacker Value
Unknown
CVE-2018-19948
Disclosure Date: September 11, 2020 (last updated February 22, 2025)
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this cross-site request forgery (CSRF) vulnerability could allow attackers to force NAS users to execute unintentional actions through a web application. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
0
Attacker Value
Unknown
CVE-2018-19946
Disclosure Date: September 11, 2020 (last updated February 22, 2025)
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this improper certificate validation vulnerability could allow an attacker to spoof a trusted entity by interfering in the communication path between the host and client. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
0
Attacker Value
Unknown
CVE-2018-19947
Disclosure Date: September 11, 2020 (last updated February 22, 2025)
The vulnerability have been reported to affect earlier versions of Helpdesk. If exploited, this information exposure vulnerability could disclose sensitive information. QNAP has already fixed the issue in Helpdesk 3.0.3 and later.
0
Attacker Value
Unknown
CVE-2020-2500
Disclosure Date: July 01, 2020 (last updated February 21, 2025)
This improper access control vulnerability in Helpdesk allows attackers to get control of QNAP Kayako service. Attackers can access the sensitive data on QNAP Kayako server with API keys. We have replaced the API key to mitigate the vulnerability, and already fixed the issue in Helpdesk 3.0.1 and later versions.
0
Attacker Value
Unknown
CVE-2020-11431
Disclosure Date: May 07, 2020 (last updated February 21, 2025)
The documentation component in i-net Clear Reports 16.0 to 19.2, HelpDesk 8.0 to 8.3, and PDFC 4.3 to 6.2 allows a remote unauthenticated attacker to read arbitrary system files and directories on the target server via Directory Traversal.
0