PT-2003-1929 · Deskpro · Deskpro

Aviram Jenik

·

Publicado

2003-10-25

·

Atualizado

2017-07-11

·

CVE-2003-0874

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions DeskPRO versions 1.1.0 and earlier
Description The issue allows remote attackers to insert arbitrary SQL and conduct unauthorized activities. This can be achieved via several parameters: the cat parameter in "faq.php", the article parameter in "faq.php", the tickedid parameter in "view.php", and the Password entry on the logon screen.
Recommendations For DeskPRO versions 1.1.0 and earlier, as a temporary workaround, consider restricting access to the "faq.php" and "view.php" files until a patch is available. Avoid using the cat, article, and tickedid parameters in their respective files, and restrict the Password entry on the logon screen to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2003-0874

Produtos afetados

Deskpro