Vulnerabilities > CVE-2005-3925 - SQL Injection vulnerability in Helpdesk Issue Manager

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
helpdesk-issue-manager
exploit available

Summary

Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.

Exploit-Db

  • descriptionHelpdesk Issue Manager 0.x find.php Multiple Parameter SQL Injection. CVE-2005-3925. Webapps exploit for php platform
    idEDB-ID:26638
    last seen2016-02-03
    modified2005-11-28
    published2005-11-28
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26638/
    titleHelpdesk Issue Manager 0.x find.php Multiple Parameter SQL Injection
  • descriptionHelpdesk Issue Manager 0.x issue.php id Parameter SQL Injection. CVE-2005-3925. Webapps exploit for php platform
    idEDB-ID:26637
    last seen2016-02-03
    modified2005-11-28
    published2005-11-28
    reporterr0t3d3Vil
    sourcehttps://www.exploit-db.com/download/26637/
    titleHelpdesk Issue Manager 0.x issue.php id Parameter SQL Injection