7.5
CVSSv2

CVE-2005-3005

Published: 21/09/2005 Updated: 18/10/2016
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Helpdesk Software Hesk allows remote malicious users to bypass authentication for (1) admin.php and (2) admin_main.php by modifying the PHPSESSID session ID parameter or cookie.

Vulnerable Product Search on Vulmon Subscribe to Product

helpdesk software hesk 0.92

helpdesk software hesk 0.93

Exploits

source: wwwsecurityfocuscom/bid/14879/info Hesk is prone to an authentication bypass vulnerability Successful exploitation will grant an attacker administrative access to the application This can lead to unauthorized access of sensitive data, modification of helpdesk data and program code, and other types of attacks 1 HTTP POST req ...