First published: Fri Oct 20 2006(Updated: )
rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain sensitive information (ticket data) via a direct request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Webgroupmedia Cerberus Helpdesk | =3.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5428 is classified as a medium severity vulnerability due to its potential for unauthorized data access.
Fixing CVE-2006-5428 involves upgrading Cerberus Helpdesk to a version that properly verifies client privileges for sensitive operations.
CVE-2006-5428 allows unauthorized users to access sensitive ticket data without proper authentication.
CVE-2006-5428 affects users of Cerberus Helpdesk version 3.2.1.
There is no official workaround for CVE-2006-5428; upgrading to a secure version is recommended.