Heathco Software h2desk Multiple Information Disclosure Vulnerabilities
BID:28062
Info
Heathco Software h2desk Multiple Information Disclosure Vulnerabilities
| Bugtraq ID: | 28062 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 01 2008 12:00AM |
| Updated: | Apr 29 2008 04:46PM |
| Credit: | joseph.giron is credited with the discovery of this vulnerability. |
| Vulnerable: |
Heathco Software h2desk 0 |
| Not Vulnerable: | |
Discussion
Heathco Software h2desk Multiple Information Disclosure Vulnerabilities
Heathco Software h2desk is prone to multiple information-disclosure vulnerabilities.
Attackers can leverage these issues to obtain potentially sensitive information that can aid in further attacks.
Heathco Software h2desk is prone to multiple information-disclosure vulnerabilities.
Attackers can leverage these issues to obtain potentially sensitive information that can aid in further attacks.
Exploit / POC
Heathco Software h2desk Multiple Information Disclosure Vulnerabilities
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?pid=databasedump
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/index.php?pid=databasedump
Solution / Fix
Heathco Software h2desk Multiple Information Disclosure Vulnerabilities
Solution:
The vendor has released a patch. Please see the references for more information.
Heathco Software h2desk 0
Solution:
The vendor has released a patch. Please see the references for more information.
Heathco Software h2desk 0
-
Heathco Software april-2008-fix.zip
http://www.heathcosoft.com/h2desk/patches/april-2008-fix.zip
References
Heathco Software h2desk Multiple Information Disclosure Vulnerabilities
References:
References:
- Vendor Homepage (Heathco Software)
- h2desk helpdesk path disclosure vulnerability ([email protected])