4.3

CVE-2006-6999

Exploit
attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Headstart SolutionsDeskpro Version2.0.0
Headstart SolutionsDeskpro Version2.0.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.04% 0.594
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

http://www.zion-security.com/text/Mul_Vulnerability_DeskPro.txt
Vendor Advisory
Exploit