PT-2009-1910 · Cerberus · Cerberus Helpdesk

Published

2009-03-06

·

Updated

2009-03-10

·

CVE-2008-6440

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Cerberus Helpdesk versions prior to 4.0 (Build 600)
Description: The issue allows remote attackers to obtain sensitive information via direct requests for certain controllers, possibly involving the "/display" and "/kb" API endpoints.
Recommendations: For versions prior to 4.0 (Build 600), update to version 4.0 (Build 600) or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-6440

Affected Products

Cerberus Helpdesk