CVE-2008-6440
06.03.2009, 18:30
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.Enginsight
Vendor | Product | Version |
---|---|---|
cerberus | cerberus_helpdesk | 2.5 |
webgroupmedia | cerberus_helpdesk | 𝑥 ≤ 3.3 |
webgroupmedia | cerberus_helpdesk | 0.97.3 |
webgroupmedia | cerberus_helpdesk | 2.0 |
webgroupmedia | cerberus_helpdesk | 2.1 |
webgroupmedia | cerberus_helpdesk | 2.2 |
webgroupmedia | cerberus_helpdesk | 2.3 |
webgroupmedia | cerberus_helpdesk | 2.4 |
webgroupmedia | cerberus_helpdesk | 2.6.1 |
webgroupmedia | cerberus_helpdesk | 2.7 |
webgroupmedia | cerberus_helpdesk | 2.7.1:development_release |
webgroupmedia | cerberus_helpdesk | 2.649 |
webgroupmedia | cerberus_helpdesk | 3.2 |
webgroupmedia | cerberus_helpdesk | 3.2.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References