Vulnerabilities > CVE-2005-3639 - Unspecified vulnerability in Ubertec Help Center Live

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN
ubertec
nessus

Summary

PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.

Vulnerable Configurations

Part Description Count
Application
Ubertec
1

Nessus

NASL familyCGI abuses
NASL idHCL_FILE_INCLUDE.NASL
descriptionThe remote host is running Help Center Live, a help desk tool written in PHP. The remote version of Help Center Live fails to sanitize input to the
last seen2020-06-01
modified2020-06-02
plugin id20223
published2005-11-18
reporterThis script is Copyright (C) 2005-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/20223
titleHelp Center Live module.php file Parameter Local File Inclusion