Vulnerabilities > Helpdezk > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-01-03 CVE-2014-8337 Unrestricted Upload of File with Dangerous Type vulnerability in Helpdezk
Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.
network
low complexity
helpdezk CWE-434
critical
9.8
2017-09-05 CVE-2017-14145 SQL Injection vulnerability in Helpdezk 1.1.1
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.
network
low complexity
helpdezk CWE-89
critical
9.8