VulnerabilityModified
CVE-2002-0932
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3)…
MEDIUM 6.4EPSS 1.25%
Does this matter?
Lower severity and a low EPSS score (1.25%). Track it; it rarely justifies an emergency change on its own.
Description
SQL injection vulnerability in index.php for MyHelpDesk 20020509, and possibly other versions, allows remote attackers to conduct unauthorized activities via SQL code in the "id" parameter for the operations (1) detailticket, (2) editticket, or (3) updateticketlog.
- CVSS 2.0
- 6.4 MEDIUMAV:N/AC:L/Au:N/C:P/I:P/A:N
- EPSS
- 1.25% probability · 68th percentile
- CISA KEV
- Not listed
- Affected
- luis bernardo/myhelpdesk
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0057.html
- http://www.iss.net/security_center/static/9321.phpVendor Advisory
- http://www.securityfocus.com/bid/4971Exploit, Vendor Advisory
- http://archives.neohapsis.com/archives/bugtraq/2002-06/0057.html
- http://www.iss.net/security_center/static/9321.phpVendor Advisory
- http://www.securityfocus.com/bid/4971Exploit, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.