Vulnerability Assessment & Network Security Forums



If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important.  If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery.


Home >> Browse Vulnerability Assessment Database >> CGI abuses >> Help Center Live osTicket Module Multiple SQL Injection Vulnerabilities


Vulnerability Assessment Details

Help Center Live osTicket Module Multiple SQL Injection Vulnerabilities

Vulnerability Assessment Summary
Tries to bypass authentication with a SQL injection attack

Detailed Explanation for this Vulnerability Assessment

Summary :

The remote web server contains a PHP application that is prone to
multiple SQL injection attacks.

Description :

The remote host is running Help Center Live, an open-source, web-based
help desk application written in PHP.

The version of Help Center Live installed on the remote host contains
a version of osTicket that is affected by multiple SQL injection
issues. An unauthenticated attacker may be able to leverage these
flaws to disclose sensitive information, modify data, bypass
authentication, or launch attacks against the underlying database.

See also :

http://sourceforge.net/project/shownotes.php?release_id=411859

Solution :

Upgrade to Help Center Live version 2.1.0 or later.

Network Security Threat Level:

High / CVSS Base Score : 7.0
(AV:R/AC:L/Au:NR/C:P/I:P/A:P/B:N)

Networks Security ID: 17676

Vulnerability Assessment Copyright: This script is Copyright (C) 2006 Tenable Network Security

Cables, Connectors


1TB 2.5

1TB 2.5" Internal Laptop TESTED Mixed Major Brands Hard Drives HDD - Tested

$24.00



Lot of 10 Laptop notebook Speed 1TB 2.5

Lot of 10 Laptop notebook Speed 1TB 2.5" SATA Hard Drive HDD Tested Wiped

$159.99



Seagate ST1000LM035 Mobile HDD 1TB 2.5

Seagate ST1000LM035 Mobile HDD 1TB 2.5" SATA III Laptop Hard Drive 0 Relocated

$18.00



2 PACK  Seagate ST1000LM035 Mobile HDD 1 TB 2.5

2 PACK Seagate ST1000LM035 Mobile HDD 1 TB 2.5" SATA III Laptop Hard Drive

$36.00



Patriot P210 128GB 256GB 512GB 1TB 2TB 2.5

Patriot P210 128GB 256GB 512GB 1TB 2TB 2.5" SATA 3 6GB/s Internal SSD PC/MAC Lot

$15.49



Samsung - 990 EVO SSD 1TB Internal SSD PCIe Gen 4x4 | Gen 5x2 M.2 2280, Speed... picture

Samsung - 990 EVO SSD 1TB Internal SSD PCIe Gen 4x4 | Gen 5x2 M.2 2280, Speed...

$69.99



Samsung - 990 EVO PLUS SSD 1TB, PCIe Gen 4x4 | 5x2 M.2 2280, Speeds Up to 7,1... picture

Samsung - 990 EVO PLUS SSD 1TB, PCIe Gen 4x4 | 5x2 M.2 2280, Speeds Up to 7,1...

$79.99



Netac 1TB 2TB 512GB Internal SSD 2.5'' SATA III 6Gb/s Solid State Drive lot picture

Netac 1TB 2TB 512GB Internal SSD 2.5'' SATA III 6Gb/s Solid State Drive lot

$46.99



1TB/2TB USB 3.0 Flash Drive Thumb U Disk Memory Stick Pen PC Laptop Storage lot picture

1TB/2TB USB 3.0 Flash Drive Thumb U Disk Memory Stick Pen PC Laptop Storage lot

$10.69



1TB HDD/SSD 2.5

1TB HDD/SSD 2.5" SATA Hard Drive for Laptop with Win 10/Win 11 Pro Pre-installed

$29.59



Discussions

No Discussions have been posted on this vulnerability.