Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Cerberus Helpdesk Multiple Input Validation Vulnerabilities

Cerberus Helpdesk is prone to multiple cross-site scripting and SQL injection vulnerabilities. These issues are the result of inadequate validation of user-supplied input that will be included in site output or in SQL queries.

The cross-site scripting vulnerability may permit a remote attacker to steal cookie-based authentication credentials from legitimate users. Successful exploitation of SQL injection vulnerabilities could result in a compromise of the application, disclosure or modification of data, or may permit an attacker to exploit vulnerabilities in the underlying database implementation.







 

Privacy Statement
Copyright 2009, SecurityFocus