7.5

CVE-2006-4539

(1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, allows remote attackers to bypass security restrictions and obtain sensitive information via the ticket parameter.  NOTE: the provenance of this information is unknown; the details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
CerberusCerberus Helpdesk Version3.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.76% 0.751
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://cerberusweb.com/cvsweb.pl/support-center/cerberus-support-center/includes/widgets/module_company_tickets.php.diff?r1=1.6%3Br2=1.7%3Bf=h
http://cerberusweb.com/cvsweb.pl/support-center/cerberus-support-center/includes/widgets/module_track_tickets.php.diff?r1=1.17%3Br2=1.18%3Bf=h
http://forum.cerberusweb.com/showthread.php?t=7671
Patch
http://secunia.com/advisories/21706
Patch
Vendor Advisory
http://securitytracker.com/id?1016976
http://www.osvdb.org/28317
http://www.securityfocus.com/bid/19797
http://www.vupen.com/english/advisories/2006/3421