First published: Sat Nov 05 2005(Updated: )
attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webgroupmedia Cerberus Helpdesk | =2.0 | |
Webgroupmedia Cerberus Helpdesk | =2.1 | |
Webgroupmedia Cerberus Helpdesk | =2.2 | |
Webgroupmedia Cerberus Helpdesk | =2.3 | |
Webgroupmedia Cerberus Helpdesk | =2.4 | |
Webgroupmedia Cerberus Helpdesk | =2.5 | |
Webgroupmedia Cerberus Helpdesk | =2.6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-3502 has a medium severity rating due to unauthorized information disclosure.
CVE-2005-3502 allows remote attackers to view attachments and tickets of other users through manipulation of the file_id parameter.
CVE-2005-3502 affects Cerberus Helpdesk versions 2.0 to 2.6.1.
To protect against CVE-2005-3502, upgrade to a patched version of Cerberus Helpdesk that addresses this vulnerability.
The potential impacts of CVE-2005-3502 include unauthorized access to sensitive user information and ticketing data.