PT-2006-5332 · Cerberus · Cerberus Helpdesk

Published

2006-09-05

·

Updated

2011-03-08

·

CVE-2006-4539

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Cerberus Helpdesk versions 3.2 Build 317 and possibly earlier
Description The issue allows remote attackers to bypass security restrictions and obtain sensitive information via the ticket parameter in certain widgets.
Recommendations For Cerberus Helpdesk versions 3.2 Build 317 and possibly earlier, consider restricting access to the module company tickets.php and module track tickets.php widgets until a fix is available. Avoid using the ticket parameter in these widgets to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-4539

Affected Products

Cerberus Helpdesk