PT-2006-6147 · Cerberus · Cerberus Helpdesk

Publicado

2006-10-20

·

Atualizado

2017-07-20

·

CVE-2006-5428

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cerberus Helpdesk version 3.2.1
Description The issue allows remote attackers to bypass the GUI login and obtain sensitive information, specifically ticket data, by sending a direct request for a display get requesters operation. This is possible because the rpc.php file in Cerberus Helpdesk does not verify a client's privileges for this operation.
Recommendations For Cerberus Helpdesk version 3.2.1, consider restricting access to the rpc.php file or the display get requesters operation until a patch is available. As a temporary workaround, limit the exposure of sensitive information by implementing additional authentication mechanisms for direct requests.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5428

Produtos afetados

Cerberus Helpdesk