PT-2006-6792 · Pmos+2 · Pmos Help Desk+2

Hacker Sun

+3

·

Published

2006-11-28

·

Updated

2018-10-17

·

CVE-2006-6158

CVSS v2.0

6.8

Medium

VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions PMOS Help Desk versions 2.4 InverseFlow Help Desk version 2.31 Ace Helpdesk version 2.31
Description The issue allows remote attackers to inject arbitrary web script or HTML, which can lead to cross-site scripting (XSS) attacks. This is possible via the id or email parameter to "ticketview.php", or the email parameter to "ticket.php".
Recommendations For PMOS Help Desk version 2.4, update to a version that fixes the XSS vulnerabilities. For InverseFlow Help Desk version 2.31, update to a version that fixes the XSS vulnerabilities. For Ace Helpdesk version 2.31, update to a version that fixes the XSS vulnerabilities.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-6158

Affected Products

Ace Helpdesk
Inverseflow Help Desk
Pmos Help Desk