PT-2003-1929 · Deskpro · Deskpro

Aviram Jenik

·

Published

2003-10-25

·

Updated

2017-07-11

·

CVE-2003-0874

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions DeskPRO versions 1.1.0 and earlier
Description The issue allows remote attackers to insert arbitrary SQL and conduct unauthorized activities. This can be achieved via several parameters: the cat parameter in "faq.php", the article parameter in "faq.php", the tickedid parameter in "view.php", and the Password entry on the logon screen.
Recommendations For DeskPRO versions 1.1.0 and earlier, as a temporary workaround, consider restricting access to the "faq.php" and "view.php" files until a patch is available. Avoid using the cat, article, and tickedid parameters in their respective files, and restrict the Password entry on the logon screen to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0874

Affected Products

Deskpro