Vulnerabilities > CVE-2006-6158

047910
CVSS 0.0 - NONE
Attack vector
UNKNOWN
Attack complexity
UNKNOWN
Privileges required
UNKNOWN
Confidentiality impact
UNKNOWN
Integrity impact
UNKNOWN
Availability impact
UNKNOWN

Summary

Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.

Vulnerable Configurations

Part Description Count
Application
Ace_Helpdesk
1
Application
Pmos_Helpdesk
1
Application
Inverseflow
1

Exploit-Db

  • descriptionPMOS Help Desk 2.3 ticket.php email Parameter XSS. CVE-2006-6158. Webapps exploit for php platform
    idEDB-ID:29166
    last seen2016-02-03
    modified2006-11-22
    published2006-11-22
    reporterSwEET-DeViL
    sourcehttps://www.exploit-db.com/download/29166/
    titlePMOS Help Desk 2.3 ticket.php email Parameter XSS
  • descriptionPMOS Help Desk 2.3 ticketview.php Multiple Parameter XSS. CVE-2006-6158. Webapps exploit for php platform
    idEDB-ID:29165
    last seen2016-02-03
    modified2006-11-22
    published2006-11-22
    reporterSwEET-DeViL
    sourcehttps://www.exploit-db.com/download/29165/
    titlePMOS Help Desk 2.3 ticketview.php Multiple Parameter XSS