CVE Database
/

CVE-2005-4427

Back to search

CVE-2005-4427

Published: Dec 20, 2005

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $addy variable in email_parser.php, (3) $address variable in email_parser.php, (4) $a_address variable in structs.php, (5) kbid parameter to cer_KnowledgebaseHandler.class.php, (6) queues[] parameter to addresses_export.php, (7) $thread variable to display.php, (8) ticket parameter to display_ticket_thread.php.

VendorProductVersions

n/a

n/a

affected
n/a

References

21991
vdb-entry
x_refsource_OSVDB
21993
vdb-entry
x_refsource_OSVDB
20051219 Cerberus Helpdesk vulnerabilities
mailing-list
x_refsource_FULLDISC
21992
vdb-entry
x_refsource_OSVDB
16062
vdb-entry
x_refsource_BID
21995
vdb-entry
x_refsource_OSVDB
21990
vdb-entry
x_refsource_OSVDB
18112
third-party-advisory
x_refsource_SECUNIA
21988
vdb-entry
x_refsource_OSVDB
21994
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now