{"api_version":"1","generated_at":"2026-07-23T06:15:37+00:00","cve":"CVE-2002-0932","urls":{"html":"https://cve.report/CVE-2002-0932","api":"https://cve.report/api/cve/CVE-2002-0932.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0932","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0932"},"summary":{"title":"CVE-2002-0932","description":"SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the \"id\" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-10-04 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/4971","name":"http://www.securityfocus.com/bid/4971","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"MyHelpDesk SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0057.html","name":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0057.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Neohapsis Archives - Bugtraq - [ARL02-A15] Multiple Security Issues in MyHelpdesk - From s_alperhotmail.com","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/9321.php","name":"http://www.iss.net/security_center/static/9321.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"ISS X-Force Database: myhelpdesk-sql-injection (9321): MyHelpdesk SQL injection","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0932","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0932","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"932","vulnerable":"1","versionEndIncluding":"2002-05-09","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"luis_bernardo","cpe5":"myhelpdesk","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T03:03:49.348Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20020610 [ARL02-A15] Multiple Security Issues in MyHelpdesk","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0057.html"},{"name":"myhelpdesk-sql-injection(9321)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/9321.php"},{"name":"4971","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4971"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-06-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the \"id\" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-09-10T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20020610 [ARL02-A15] Multiple Security Issues in MyHelpdesk","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0057.html"},{"name":"myhelpdesk-sql-injection(9321)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/9321.php"},{"name":"4971","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4971"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0932","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the \"id\" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20020610 [ARL02-A15] Multiple Security Issues in MyHelpdesk","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2002-06/0057.html"},{"name":"myhelpdesk-sql-injection(9321)","refsource":"XF","url":"http://www.iss.net/security_center/static/9321.php"},{"name":"4971","refsource":"BID","url":"http://www.securityfocus.com/bid/4971"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0932","datePublished":"2002-08-31T04:00:00.000Z","dateReserved":"2002-08-16T00:00:00.000Z","dateUpdated":"2024-08-08T03:03:49.348Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-10-04 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:luis_bernardo:myhelpdesk:*:*:*:*:*:*:*:*","versionEndIncluding":"2002-05-09","matchCriteriaId":"0DE9BDC6-3D87-4820-BFB9-1B1F1562FD44"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"932","Ordinal":"1","Title":"CVE-2002-0932","CVE":"CVE-2002-0932","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"932","Ordinal":"1","NoteData":"SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the \"id\" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog.","Type":"Description","Title":"CVE-2002-0932"},{"CveYear":"2002","CveId":"932","Ordinal":"2","NoteData":"2002-08-31","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"932","Ordinal":"3","NoteData":"2002-09-10","Type":"Other","Title":"Modified"}]}}}