VulnerabilityModified
CVE-2008-6440
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.
MEDIUM 5.0EPSS 1.16%
Does this matter?
Lower severity and a low EPSS score (1.16%). Track it; it rarely justifies an emergency change on its own.
Description
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.16% probability · 65th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- cerberus/cerberus helpdesk · webgroupmedia/cerberus helpdesk
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/30344Vendor Advisory
- http://www.cerb4.com/blog/2008/05/15/important-security-patch-40-build-599/Vendor Advisory
- http://www.securityfocus.com/bid/29335
- http://secunia.com/advisories/30344Vendor Advisory
- http://www.cerb4.com/blog/2008/05/15/important-security-patch-40-build-599/Vendor Advisory
- http://www.securityfocus.com/bid/29335
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.