CVE-2006-4539
(1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, allows remote attackers to bypass security restrictions and obtain…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.77%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
(1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, allows remote attackers to bypass security restrictions and obtain sensitive information via the ticket parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.77% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- cerberus/cerberus helpdesk
- Source
- cve@mitre.org
References
- http://cerberusweb.com/cvsweb.pl/support-center/cerberus-support-center/includes/widgets/module_company_tickets.php.diff?r1=1.6%3Br2=1.7%3Bf=h
- http://cerberusweb.com/cvsweb.pl/support-center/cerberus-support-center/includes/widgets/module_track_tickets.php.diff?r1=1.17%3Br2=1.18%3Bf=h
- http://forum.cerberusweb.com/showthread.php?t=7671Patch
- http://secunia.com/advisories/21706Patch, Vendor Advisory
- http://securitytracker.com/id?1016976
- http://www.osvdb.org/28317
- http://www.securityfocus.com/bid/19797
- http://www.vupen.com/english/advisories/2006/3421
- http://cerberusweb.com/cvsweb.pl/support-center/cerberus-support-center/includes/widgets/module_company_tickets.php.diff?r1=1.6%3Br2=1.7%3Bf=h
- http://cerberusweb.com/cvsweb.pl/support-center/cerberus-support-center/includes/widgets/module_track_tickets.php.diff?r1=1.17%3Br2=1.18%3Bf=h
- http://forum.cerberusweb.com/showthread.php?t=7671Patch
- http://secunia.com/advisories/21706Patch, Vendor Advisory
- http://securitytracker.com/id?1016976
- http://www.osvdb.org/28317
- http://www.securityfocus.com/bid/19797
- http://www.vupen.com/english/advisories/2006/3421
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.