Cerberus Helpdesk Information Disclosure Vulnerability
BID:15315
Info
Cerberus Helpdesk Information Disclosure Vulnerability
| Bugtraq ID: | 15315 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 04 2005 12:00AM |
| Updated: | Nov 04 2005 12:00AM |
| Credit: | cumhur onat is credited with the discovery of this vulnerability. |
| Vulnerable: |
Cerberus Helpdesk 2.6.1 Cerberus Helpdesk 2.5 Cerberus Helpdesk 2.4 Cerberus Helpdesk 2.3 Cerberus Helpdesk 2.2 Cerberus Helpdesk 2.1 Cerberus Helpdesk 2.0 |
| Not Vulnerable: | |
Discussion
Cerberus Helpdesk Information Disclosure Vulnerability
Cerberus Helpdesk is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary email attachments of other users in the security context of the Web server process. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.
Cerberus Helpdesk is prone to an information disclosure vulnerability. This issue is due to a failure in the application to properly sanitize user-supplied input.
An attacker can exploit this vulnerability to retrieve arbitrary email attachments of other users in the security context of the Web server process. Information obtained may aid in further attacks against the underlying system; other attacks are also possible.
Exploit / POC
Cerberus Helpdesk Information Disclosure Vulnerability
No exploit is required.
No exploit is required.
Solution / Fix
Cerberus Helpdesk Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.