6.4
CVSSv2

CVE-2002-0932

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 645
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote malicious users to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog.

Vulnerable Product Search on Vulmon Subscribe to Product

luis bernardo myhelpdesk

Exploits

source: wwwsecurityfocuscom/bid/4971/info It is reported that MyHelpDesk (version 20020509 and earlier) are vulnerable to SQL injection attacks Data supplied by the remote user, via CGI parameters, is used directly as part of SQL statements As input sanitization is not properly performed, it is possible to modify the logic of a SQL que ...