Show filters
83 Total Results
Displaying 51-60 of 83
Sort by:
Attacker Value
Unknown
CVE-2008-6380
Disclosure Date: March 02, 2009 (last updated October 04, 2023)
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL commands via the CategoryID parameter.
0
Attacker Value
Unknown
CVE-2008-0605
Disclosure Date: February 06, 2008 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message.
0
Attacker Value
Unknown
CVE-2007-6550
Disclosure Date: December 28, 2007 (last updated October 04, 2023)
form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.
0
Attacker Value
Unknown
CVE-2007-6347
Disclosure Date: December 13, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Shop Evaluation 3.3.2, and (4) Shop Free 3.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the root_folder_path parameter. NOTE: some of these details are obtained from third party information.
0
Attacker Value
Unknown
CVE-2007-5916
Disclosure Date: November 10, 2007 (last updated October 04, 2023)
SQL injection vulnerability in the login page in phphelpdesk 0.6.16 allows remote attackers to execute arbitrary SQL commands via unspecified parameters related to the "login procedures."
0
Attacker Value
Unknown
CVE-2007-5915
Disclosure Date: November 10, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in phphelpdesk 0.6.16 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the whattodo parameter.
0
Attacker Value
Unknown
CVE-2007-5727
Disclosure Date: October 30, 2007 (last updated October 04, 2023)
Incomplete blacklist vulnerability in the stripScripts function in common.php in OneOrZero Helpdesk 1.6.5.4, 1.6.4.2, and possibly other versions, allows remote attackers to conduct cross-site scripting (XSS) attacks and inject arbitrary web script or HTML via XSS sequences without SCRIPT tags in the description parameter to (1) tcreate.php or (2) tupdate.php, as demonstrated using an onmouseover event in a b tag.
0
Attacker Value
Unknown
CVE-2007-5176
Disclosure Date: October 03, 2007 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in GroupLink eHelpDesk 6.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) NA_DISPLAYNAME parameter in helpdesk/user/rf_create.jsp and the (2) username and (3) LDAPError parameters in index2.jsp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
0
Attacker Value
Unknown
CVE-2006-6380
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.
0
Attacker Value
Unknown
CVE-2006-6381
Disclosure Date: December 07, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
0