Show filters
83 Total Results
Displaying 31-40 of 83
Sort by:
Attacker Value
Unknown
CVE-2019-20002
Disclosure Date: April 27, 2020 (last updated February 21, 2025)
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by an admin user.
0
Attacker Value
Unknown
CVE-2018-0728
Disclosure Date: December 04, 2019 (last updated November 27, 2024)
This improper access control vulnerability in Helpdesk allows attackers to access the system logs. To fix the vulnerability, QNAP recommend updating QTS and Helpdesk to their latest versions.
0
Attacker Value
Unknown
CVE-2017-18486
Disclosure Date: August 09, 2019 (last updated November 27, 2024)
Jitbit Helpdesk before 9.0.3 allows remote attackers to escalate privileges because of mishandling of the User/AutoLogin userHash parameter. By inspecting the token value provided in a password reset link, a user can leverage a weak PRNG to recover the shared secret used by the server for remote authentication. The shared secret can be used to escalate privileges by forging new tokens for any user. These tokens can be used to automatically log in as the affected user.
0
Attacker Value
Unknown
CVE-2018-0714
Disclosure Date: August 13, 2018 (last updated November 27, 2024)
Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.
0
Attacker Value
Unknown
CVE-2017-13068
Disclosure Date: October 06, 2017 (last updated November 26, 2024)
QNAP has already patched this vulnerability. This security concern allows a remote attacker to perform an SQL injection on the application and obtain Helpdesk application information. A remote attacker does not require any privileges to successfully execute this attack.
0
Attacker Value
Unknown
CVE-2017-14320
Disclosure Date: September 21, 2017 (last updated November 26, 2024)
Mirasvit Helpdesk MX before 1.5.3 might allow remote attackers to execute arbitrary code by leveraging failure to filter uploaded files.
0
Attacker Value
Unknown
CVE-2017-14321
Disclosure Date: September 21, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the administrative interface in Mirasvit Helpdesk MX before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) customer name or (2) subject in a ticket.
0
Attacker Value
Unknown
CVE-2015-4074
Disclosure Date: September 20, 2017 (last updated November 26, 2024)
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.
0
Attacker Value
Unknown
CVE-2015-4072
Disclosure Date: September 20, 2017 (last updated November 26, 2024)
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message.
0
Attacker Value
Unknown
CVE-2015-4073
Disclosure Date: September 20, 2017 (last updated November 26, 2024)
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter.
0