First published: Tue Jun 14 2005(Updated: )
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webgroupmedia Cerberus Helpdesk | =0.97.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-1963 is considered a medium severity vulnerability due to the exposure of sensitive information.
To fix CVE-2005-1963, ensure that all access to reports.php, knowledgebase.php, and configuration.php is restricted to authorized users only.
CVE-2005-1963 can lead to exposure of sensitive information such as configuration settings and database credentials through PHP error messages.
CVE-2005-1963 specifically affects Cerberus Helpdesk version 0.97.3.
Yes, CVE-2005-1963 is exploitable remotely, allowing attackers to access sensitive information without local access.