Show filters
83 Total Results
Displaying 71-80 of 83
Sort by:
Attacker Value
Unknown
CVE-2005-4427
Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to cer_KnowledgebaseHandler.class.php, (6) queues[] parameter to addresses_export.php, (7) $thread variable to display.php, (8) ticket parameter to display_ticket_thread.php.
0
Attacker Value
Unknown
CVE-2005-3925
Disclosure Date: November 30, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.
0
Attacker Value
Unknown
CVE-2005-3826
Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter.
0
Attacker Value
Unknown
CVE-2005-3502
Disclosure Date: November 05, 2005 (last updated February 22, 2025)
attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.
0
Attacker Value
Unknown
CVE-2005-1963
Disclosure Date: June 16, 2005 (last updated February 22, 2025)
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.
0
Attacker Value
Unknown
CVE-2005-1962
Disclosure Date: June 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.
0
Attacker Value
Unknown
CVE-2004-2562
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown
CVE-2004-2737
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.
0
Attacker Value
Unknown
CVE-2004-2736
Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.
0
Attacker Value
Unknown
CVE-2003-0303
Disclosure Date: June 09, 2003 (last updated February 22, 2025)
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.
0