Helpdesk Issue Manager Multiple SQL Injection Vulnerabilities

No exploit is required.

The following proof of concept examples are available:
http://www.example.com/issue.php?id=[SQL]
http://www.example.com/find.php?act=action&reset=yes&detail%5B%5D=[SQL]
http://www.example.com/find.php?page=0&act=action&orderby=sortorder&orderdir=[SQL]
http://www.example.com/find.php?page=0&act=action&orderby=[SQL]


 

Privacy Statement
Copyright 2010, SecurityFocus