PT-2006-5332 · Cerberus · Cerberus Helpdesk

Publicado

2006-09-05

·

Atualizado

2011-03-08

·

CVE-2006-4539

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cerberus Helpdesk versions 3.2 Build 317 and possibly earlier
Description The issue allows remote attackers to bypass security restrictions and obtain sensitive information via the ticket parameter in certain widgets.
Recommendations For Cerberus Helpdesk versions 3.2 Build 317 and possibly earlier, consider restricting access to the module company tickets.php and module track tickets.php widgets until a fix is available. Avoid using the ticket parameter in these widgets to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-4539

Produtos afetados

Cerberus Helpdesk