Vulnerabilities (CVE)

Filtered by vendor Astrosoft Subscribe
Filtered by product Astrosoft Helpdesk
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2008-0605 1 Astrosoft 1 Astrosoft Helpdesk 2024-02-04 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message.