RSS   Vulnerabilities for 'Web help desk'   RSS

2022-03-10
 
CVE-2021-35251

CWE-209
 

 
Sensitive information could be displayed when a detailed technical error message is posted. This information could disclose environmental details about the Web Help Desk installation.

 
2021-08-26
 
CVE-2021-32076

CWE-863
 

 
Access Restriction Bypass via referrer spoof was discovered in SolarWinds Web Help Desk 12.7.2. An attacker can access the 'Web Help Desk Getting Started Wizard', especially the admin account creation page, from a non-privileged IP address network range or loopback address by intercepting the HTTP request and changing the referrer from the public IP address to the loopback.

 
2021-01-15
 
CVE-2019-16961

CWE-79
 

 
SolarWinds Web Help Desk 12.7.0 allows XSS via a Schedule Name.

 
2021-01-06
 
CVE-2019-16954

CWE-74
 

 
SolarWinds Web Help Desk 12.7.0 allows HTML injection via a Comment in a Help Request ticket.

 
2021-01-04
 
CVE-2019-16960

CWE-79
 

 
SolarWinds Web Help Desk 12.7.0 allows XSS via a CSV template file with a crafted Location Name field.

 
 
CVE-2019-16956

CWE-79
 

 
SolarWinds Web Help Desk 12.7.0 allows XSS via the Request Type parameter of a ticket.

 

 >>> Vendor: Solarwinds 46 Products
Serv-u
Tftp server
Ftp voyager
Patch manager
Help desk
Kiwi cattools
Web help desk
Orion network performance monitor
Virtualization manager
Ip address manager web interface
Network configuration manager
Log and event manager
Server and application monitor
Orion ip address manager
Orion netflow traffic analyzer
Orion network configuration manager
Orion server and application manager
Orion user device tracker
Orion voip & network quality manager
Orion web performance monitor
Firewall security manager
Storage manager
N-able n-central
Storage resource monitor
Log & event manager
Network performance monitor
Sftp/scp server
Orion platform
Serv-u ftp server
Damewire mini remote control
Database performance analyzer
Dameware mini remote control firmware
Dameware remote support
N-central
Netpath
Serv-u managed file transfer
Dameware
Managed service provider patch management engine
Advanced monitoring agent
Webhelpdesk
Orion virtual infrastructure monitor
Serv-u file server
Dameware mini remote control
Pingdom
Kiwi syslog server
Access rights manager


Copyright 2024, cxsecurity.com

 

Back to Top