Vulnerabilities > CVE-2005-1673 - Unspecified vulnerability in Ubertec Help Center Live

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ubertec
nessus
exploit available

Summary

Multiple SQL injection vulnerabilities in Help Center Live allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to index.php, (2) tid parameter to view.php, fid parameter to (3) download.php or (4) chat_download.php, (5) status parameter to icon.php, TICKET_tid parameter to (6) index.php or (7) view.php.

Vulnerable Configurations

Part Description Count
Application
Ubertec
1

Exploit-Db

descriptionHelpCenter Live! < 1.2.7 - Multiple Vulnerabilities. CVE-2005-1672,CVE-2005-1673,CVE-2005-1674. Webapps exploit for PHP platform
idEDB-ID:43814
last seen2018-01-24
modified2004-05-17
published2004-05-17
reporterExploit-DB
sourcehttps://www.exploit-db.com/download/43814/
titleHelpCenter Live! < 1.2.7 - Multiple Vulnerabilities

Nessus

NASL familyCGI abuses
NASL idHCL_MULT_VULNS.NASL
descriptionThe remote host is running Help Center Live, a help desk written in PHP that suffers from multiple vulnerabilities: - Multiple SQL Injection Vulnerabilities The application fails in many cases to sanitize user- supplied input before using it in database queries. As long as PHP
last seen2020-06-01
modified2020-06-02
plugin id18296
published2005-05-18
reporterThis script is Copyright (C) 2005-2018 Tenable Network Security, Inc.
sourcehttps://www.tenable.com/plugins/nessus/18296
titleHelp Center Live Multiple Vulnerabilities (SQLi, XSS, CSRF)