Cerberus Helpdesk Rpc.PHP Unauthorized Access Vulnerability
BID:20598
Info
Cerberus Helpdesk Rpc.PHP Unauthorized Access Vulnerability
| Bugtraq ID: | 20598 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 18 2006 12:00AM |
| Updated: | Oct 19 2006 02:09AM |
| Credit: | jonepet is credited with the discovery of this vulnerability. |
| Vulnerable: |
Cerberus Helpdesk 3.2.1 |
| Not Vulnerable: | |
Discussion
Cerberus Helpdesk Rpc.PHP Unauthorized Access Vulnerability
Cerberus Helpdesk is prone to an unauthorized-access vulnerability because the application fails to authenticate users properly, resulting in an improper-access validation. A workaround is available.
An attacker can exploit this vulnerability to retrieve other users' arbitrary ticket data. Information obtained can lead to a compromise of other users' confidential information.
Version 3.2.1 is affected by this issue; other versions may be vulnerable as well.
Cerberus Helpdesk is prone to an unauthorized-access vulnerability because the application fails to authenticate users properly, resulting in an improper-access validation. A workaround is available.
An attacker can exploit this vulnerability to retrieve other users' arbitrary ticket data. Information obtained can lead to a compromise of other users' confidential information.
Version 3.2.1 is affected by this issue; other versions may be vulnerable as well.
Exploit / POC
Cerberus Helpdesk Rpc.PHP Unauthorized Access Vulnerability
Attackers can exploit this issue via a web client.
A proof-of-concept URI is as follows:
http://www.example.com/rpc.php?cmd=display_get_requesters&id=[ticket#]
Attackers can exploit this issue via a web client.
A proof-of-concept URI is as follows:
http://www.example.com/rpc.php?cmd=display_get_requesters&id=[ticket#]
Solution / Fix
Cerberus Helpdesk Rpc.PHP Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
Cerberus Helpdesk Rpc.PHP Unauthorized Access Vulnerability
References:
References:
- HelpDesk Product Page (Cerberus)
- Helpdesk Support Page (Cerberus)
- Possibility to read requesters, workflow, etc. through rpc.php without login (Cerberus)