Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user.
References
Link | Resource |
---|---|
http://securitytracker.com/id?1015307 | Exploit Vendor Advisory |
http://securitytracker.com/id?1015307 | Exploit Vendor Advisory |
Configurations
History
21 Nov 2024, 00:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://securitytracker.com/id?1015307 - Exploit, Vendor Advisory |
Information
Published : 2005-12-05 11:03
Updated : 2025-04-03 01:03
NVD link : CVE-2005-4025
Mitre link : CVE-2005-4025
CVE.ORG link : CVE-2005-4025
JSON object : View
Products Affected
help_desk_reloaded
- free_help_desk
CWE