Vulnerabilities > CVE-2004-2603 - Unspecified vulnerability in Ubertec Help Center Live
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN ubertec
nessus
Summary
Cross-site scripting (XSS) vulnerability in the Search module in UberTec Help Center Live (HCL) allows remote attackers to inject arbitrary web script or HTML via the find parameter to index.php.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 8 |
Nessus
NASL family | CGI abuses |
NASL id | HELP_CENTER_FILE_INCLUDE.NASL |
description | The remote host is running Help Center Live, a help desk application written in PHP. The remote version of this software is vulnerable to various flaws, including one that may allow an attacker to execute arbitrary commands on the remote host subject to the privileges of the web server user id provided PHP |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 16060 |
published | 2004-12-28 |
reporter | This script is Copyright (C) 2004-2019 and is owned by Tenable, Inc. or an Affiliate thereof. |
source | https://www.tenable.com/plugins/nessus/16060 |
title | Help Center Live Multiple Remote Vulnerabilities (Cmd Exec, XSS) |
code |
|
References
- http://secunia.com/advisories/13652
- http://secunia.com/advisories/13652
- http://securitytracker.com/id?1012685
- http://securitytracker.com/id?1012685
- http://www.gulftech.org/?node=research&article_id=00058-12242004
- http://www.gulftech.org/?node=research&article_id=00058-12242004
- http://www.osvdb.org/12597
- http://www.osvdb.org/12597
- http://www.securityfocus.com/bid/12105
- http://www.securityfocus.com/bid/12105
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18696
- https://exchange.xforce.ibmcloud.com/vulnerabilities/18696