First published: Wed Feb 01 2006(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the contact_search parameter and (2) unspecified url fields.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webgroupmedia Cerberus Helpdesk | =2.7 | |
Webgroupmedia Cerberus Helpdesk | =2.7.1_development_release |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2006-0509 is considered medium due to the potential for exploitation via cross-site scripting.
To fix CVE-2006-0509, users should apply any available patches or updates from the Cerberus Helpdesk vendor.
CVE-2006-0509 affects Cerberus Helpdesk versions 2.7 and 2.7.1 development release.
CVE-2006-0509 is a cross-site scripting (XSS) vulnerability that allows the injection of arbitrary web scripts.
Yes, CVE-2006-0509 can be exploited remotely by attackers through the affected parameters.