Show filters
83 Total Results
Displaying 71-80 of 83
Sort by:
Attacker Value
Unknown

CVE-2005-4427

Disclosure Date: December 20, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to cer_KnowledgebaseHandler.class.php, (6) queues[] parameter to addresses_export.php, (7) $thread variable to display.php, (8) ticket parameter to display_ticket_thread.php.
0
Attacker Value
Unknown

CVE-2005-3925

Disclosure Date: November 30, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.
0
Attacker Value
Unknown

CVE-2005-3826

Disclosure Date: November 26, 2005 (last updated February 22, 2025)
Multiple SQL injection vulnerabilities in Ezyhelpdesk 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) edit_id, (2) faq_id, and (3) c_id parameters in a query string, and (4) the search engine, possibly involving the search_string parameter.
0
Attacker Value
Unknown

CVE-2005-3502

Disclosure Date: November 05, 2005 (last updated February 22, 2025)
attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.
0
Attacker Value
Unknown

CVE-2005-1963

Disclosure Date: June 16, 2005 (last updated February 22, 2025)
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.
0
Attacker Value
Unknown

CVE-2005-1962

Disclosure Date: June 16, 2005 (last updated February 22, 2025)
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or (2) certain fields to clients.php.
0
Attacker Value
Unknown

CVE-2004-2562

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in jobedit.asp in Leigh Business Enterprises (LBE) Web Helpdesk before 4.0.0.81 allows remote attackers to execute arbitrary SQL commands via the id parameter.
0
Attacker Value
Unknown

CVE-2004-2737

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
SQL injection vulnerability in problist.asp in NetSupport DNA HelpDesk 1.01 allows remote attackers to execute arbitrary SQL commands via the where parameter.
0
Attacker Value
Unknown

CVE-2004-2736

Disclosure Date: December 31, 2004 (last updated February 22, 2025)
Polar HelpDesk 3.0 allows remote attackers to bypass authentication by setting the UserId and UserType values in a cookie.
0
Attacker Value
Unknown

CVE-2003-0303

Disclosure Date: June 09, 2003 (last updated February 22, 2025)
SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.
0