RSS   Vulnerabilities for 'Helpdezk'   RSS

2020-01-03
 
CVE-2014-8337

CWE-434
 

 
Unrestricted file upload vulnerability in includes/classes/uploadify-v2.1.4/uploadify.php in HelpDEZk 1.0.1 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in the directory specified by the folder parameter.

 
2017-09-05
 
CVE-2017-14146

 

 
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.

 
 
CVE-2017-14145

 

 
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.

 
2017-04-05
 
CVE-2017-7447

 

 
HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.

 
 
CVE-2017-7446

 

 
HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.

 


Copyright 2024, cxsecurity.com

 

Back to Top