Vulnerabilities > CVE-2005-1672 - Unspecified vulnerability in Ubertec Help Center Live

047910
CVSS 4.3 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
ubertec
nessus
exploit available

Summary

Multiple cross-site scripting (XSS) vulnerabilities in Help Center Live allow remote attackers to inject arbitrary web script or HTML via the (1) find parameter to index.php, (2) name or (3) message field of a chat request, or (4) the message body when opening a trouble ticket.

Vulnerable Configurations

Part Description Count
Application
Ubertec
1

Exploit-Db

descriptionHelpCenter Live! < 1.2.7 - Multiple Vulnerabilities. CVE-2005-1672,CVE-2005-1673,CVE-2005-1674. Webapps exploit for PHP platform
idEDB-ID:43814
last seen2018-01-24
modified2004-05-17
published2004-05-17
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43814/
titleHelpCenter Live! < 1.2.7 - Multiple Vulnerabilities

Nessus

NASL familyCGI abuses
NASL idHCL_MULT_VULNS.NASL
descriptionThe remote host is running Help Center Live, a help desk written in PHP that suffers from multiple vulnerabilities: - Multiple SQL Injection Vulnerabilities The application fails in many cases to sanitize user- supplied input before using it in database queries. As long as PHP
last seen2020-06-01
modified2020-06-02
plugin id18296
published2005-05-18
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/18296
titleHelp Center Live Multiple Vulnerabilities (SQLi, XSS, CSRF)