AstroSoft HelpDesk Multiple Cross-Site Scripting Vulnerabilities
BID:27610
Info
AstroSoft HelpDesk Multiple Cross-Site Scripting Vulnerabilities
| Bugtraq ID: | 27610 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-0605 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2008 12:00AM |
| Updated: | Apr 16 2015 06:06PM |
| Credit: | Alexandr Polyakov and Stas Svistunovich of Digital Security Research Group are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
AstroSoft AstroSoft HelpDesk 0 |
| Not Vulnerable: |
AstroSoft AstroSoft HelpDesk 1.95.228 |
Discussion
AstroSoft HelpDesk Multiple Cross-Site Scripting Vulnerabilities
AstroSoft HelpDesk is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
AstroSoft HelpDesk is prone to multiple cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input.
An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks.
Exploit / POC
Solution / Fix
AstroSoft HelpDesk Multiple Cross-Site Scripting Vulnerabilities
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
AstroSoft HelpDesk Multiple Cross-Site Scripting Vulnerabilities
References:
References:
- AstroSoft HelpDesk Homepage (AstroSoft)
- [DSECRG-08-011 | FIX INFORMATION] Astrosoft HelpDesk Multiple XSS (Digital Security Research Group \[DSecRG\]"
) - [DSECRG-08-011] Astrosoft HelpDesk Multiple XSS (Digital Security Research Group
)