Vulnerabilities > CVE-2007-4240 - Security Bypass vulnerability in Help Center Live Help Center Live 2.1.3A

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
help-center-live
nessus

Summary

The check_logout function in class/auth.php in Help Center Live (hcl) 2.1.3a sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to delete administrative users and have other unspecified impact via certain requests to (1) admin/departments.php, (2) admin/operators.php, and other unspecified scripts. NOTE: some of these details are obtained from third party information.

Vulnerable Configurations

Part Description Count
Application
Help_Center_Live
1

Nessus

NASL familyCGI abuses
NASL idHCL_ADMIN_BYPASS.NASL
descriptionThe remote host is running Help Center Live, an open source, web-based help desk application written in PHP. The version of Help Center Live installed on the remote host has several administrative scripts that fail to exit if called without valid credentials. An unauthenticated attacker may be able to exploit this design flaw to gain administrative control of the application.
last seen2020-06-01
modified2020-06-02
plugin id25898
published2007-08-16
reporterThis script is Copyright (C) 2007-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/25898
titleHelp Center Live class/auth.php check_logout Function Admin Authentication Bypass