7.5
CVSSv2

CVE-2007-6550

Published: 28/12/2007 Updated: 29/09/2017
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

form.php in PMOS Help Desk 2.4 and previous versions sends a redirect to the web browser but does not exit, which allows remote malicious users to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

pmos helpdesk pmos helpdesk

Exploits

<?php /* ------------------------------------------------------ PMOS Help Desk <= 24 Remote Command Execution Exploit ------------------------------------------------------ author: EgiX mail: n0b0d13s[at]gmail[dot]com link: wwwh2deskcom/pmos dork: "Powered by PMOS Help Desk" [-] PHP code injection th ...