Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
deskpro vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2007-1012
Cross-site scripting (XSS) vulnerability in faq.php in DeskPRO 1.1.0 allows remote malicious users to inject arbitrary web script or HTML via the article parameter.
Deskpro Deskpro 1.1.0
3.5
CVSSv2
CVE-2021-36696
Deskpro cloud and on-premise Deskpro 2021.1.6 and fixed in Deskpro 2021.1.7 contains a cross-site scripting (XSS) vulnerability in social media links on a user profile due to lack of input validation.
Deskpro Deskpro 2021.1.6
5
CVSSv2
CVE-2003-0874
Multiple SQL injection vulnerabilities in DeskPRO 1.1.0 and previous versions allow remote malicious users to insert arbitrary SQL and conduct unauthorized activities via (1) the cat parameter in faq.php, (2) the article parameter in faq.php, (3) the tickedid parameter in view.ph...
Deskpro Deskpro 1.1 .0
5
CVSSv2
CVE-2006-7000
Headstart Solutions DeskPRO allows remote malicious users to obtain the full path via direct requests to (1) email/mail.php, (2) includes/init.php, (3) certain files in includes/cron/, and (4) jpgraph.php, (5) jpgraph_bar.php, (6) jpgraph_pie.php, and (7) jpgraph_pie3d.php in inc...
Headstart Solutions Deskpro 2.0.0
Headstart Solutions Deskpro 2.0.1
5
CVSSv2
CVE-2006-6998
install/loader_help.php in Headstart Solutions DeskPRO allows remote malicious users to obtain configuration information via a q=phpinfo QUERY_STRING, which calls the phpinfo function.
Headstart Solutions Deskpro 2.0.0
Headstart Solutions Deskpro 2.0.1
4.3
CVSSv2
CVE-2006-6999
attachment.php in Headstart Solutions DeskPRO allows remote malicious users to read all uploaded files by providing the file number in a modified id parameter.
Headstart Solutions Deskpro 2.0.0
Headstart Solutions Deskpro 2.0.1
7.5
CVSSv2
CVE-2006-6973
Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote malicious users to (1) reinstall the application via a direct request for install/index.php; (2) delete the database via a ...
Headstart Solutions Deskpro
7.5
CVSSv2
CVE-2006-6974
Headstart Solutions DeskPRO stores sensitive information under the web root with insufficient access control, which allows remote malicious users to (1) list files in the includes/ directory; obtain the SQL username and password via a direct request for (2) config.php and (3) con...
Headstart Solutions Deskpro
3.5
CVSSv2
CVE-2007-4413
Direct static code injection vulnerability in admincp/user_help.php in Headstart Solutions DeskPRO 3.0.2 allows remote authenticated users to inject arbitrary PHP code into an unspecified file via a new_entry value in the do parameter.
Headstart Solutions Deskpro 3.0.2
3.5
CVSSv2
CVE-2007-4412
Multiple cross-site scripting (XSS) vulnerabilities in Headstart Solutions DeskPRO 3.0.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (1) techs.php, (2) ticket_category.php, (3) ticket_priority.php, (4) ticket_workflow.php,...
Headstart Solutions Deskpro 3.0.2
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
cross-site request forgery
unauthorized
CVE-2024-33925
reflected XSS
CVE-2023-51580
CVE-2023-51579
CVE-2015-2051
CVE-2023-51609
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
NEXT »