Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
help desk vulnerabilities and exploits
(subscribe to this query)
5
CVSSv2
CVE-2021-35251
Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation.
Solarwinds Web Help Desk
NA
CVE-2023-1125
The Ruby Help Desk WordPress plugin prior to 1.3.4 does not ensure that the ticket being modified belongs to the user making the request, allowing an malicious user to close and/or add files and replies to tickets other than their own.
Wpruby Ruby Help Desk
5
CVSSv2
CVE-2008-6057
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, which allows remote malicious users to obtain passwords via a direct request.
Liberum Liberum Help Desk 0.97.3
1 EDB exploit
4.9
CVSSv2
CVE-2019-16954
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.
Solarwinds Web Help Desk 12.7.0
3.5
CVSSv2
CVE-2019-16956
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.
Solarwinds Web Help Desk 12.7.0
3.5
CVSSv2
CVE-2019-16960
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.
Solarwinds Web Help Desk 12.7.0
3.5
CVSSv2
CVE-2019-16961
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.
Solarwinds Web Help Desk 12.7.0
4.3
CVSSv2
CVE-2009-1261
Multiple cross-site scripting (XSS) vulnerabilities in Web Help Desk 9.1.22 (evaluation version) allow remote malicious users to inject arbitrary web script or HTML via the (1) Report Name, (2) Asset No., and (3) Full Name fields in a Models action. NOTE: the provenance of this i...
Webhelpdesk Web Help Desk 9.1.22
7.5
CVSSv2
CVE-2005-4628
SQL injection vulnerability in index.php in HelpDeskPoint 2.38 and previous versions allows remote malicious users to execute arbitrary SQL commands via the page parameter.
Help Desk Point Software Helpdeskpoint
7.5
CVSSv2
CVE-2006-6161
Multiple SQL injection vulnerabilities in Doug Luxem Liberum Help Desk 0.97.3 and previous versions allow remote malicious users to execute arbitrary SQL commands via the (1) id and (2) uid parameter to (a) inout/status.asp, (b) inout/update.asp, and (c) forgotpass.asp. NOTE: The...
Doug Luxem Liberum Help Desk
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »