Vulnerabilities > CVE-2005-3639 - Local File Include vulnerability in Help Center Live

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
ubertec
nessus

Summary

PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.

Vulnerable Configurations

Part Description Count
Application
Ubertec
1

Nessus

NASL familyCGI abuses
NASL idHCL_FILE_INCLUDE.NASL
descriptionThe remote host is running Help Center Live, a help desk tool written in PHP. The remote version of Help Center Live fails to sanitize input to the
last seen2020-06-01
modified2020-06-02
plugin id20223
published2005-11-18
reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/20223
titleHelp Center Live module.php file Parameter Local File Inclusion