RSS   Vulnerabilities for 'Ultimate helpdesk'   RSS

2006-12-07
 
CVE-2006-6381

 

 
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

 
 
CVE-2006-6380

 

 
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

 


Copyright 2024, cxsecurity.com

 

Back to Top