PT-2006-6792 · Pmos+2 · Pmos Help Desk+2
Hacker Sun
+3
·
Published
2006-11-28
·
Updated
2018-10-17
·
CVE-2006-6158
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
PMOS Help Desk versions 2.4
InverseFlow Help Desk version 2.31
Ace Helpdesk version 2.31
Description
The issue allows remote attackers to inject arbitrary web script or HTML, which can lead to cross-site scripting (XSS) attacks. This is possible via the
id or email parameter to "ticketview.php", or the email parameter to "ticket.php".Recommendations
For PMOS Help Desk version 2.4, update to a version that fixes the XSS vulnerabilities.
For InverseFlow Help Desk version 2.31, update to a version that fixes the XSS vulnerabilities.
For Ace Helpdesk version 2.31, update to a version that fixes the XSS vulnerabilities.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ace Helpdesk
Inverseflow Help Desk
Pmos Help Desk