form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.
References
Configurations
History
No history.
Information
Published : 2007-12-28 00:46
Updated : 2024-02-04 17:13
NVD link : CVE-2007-6550
Mitre link : CVE-2007-6550
CVE.ORG link : CVE-2007-6550
JSON object : View
Products Affected
pmos_helpdesk
- pmos_helpdesk
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')