Help Desk Reloaded Free Help Desk does not remove or protect install.php once installation is complete, which allows remote attackers to gain privileges via a direct request to install.php, then navigating to accountsetup.php and creating a new user.
References
Link | Resource |
---|---|
http://securitytracker.com/id?1015307 | Exploit Vendor Advisory |
Configurations
Information
Published : 2005-12-05 03:03
Updated : 2008-09-05 13:55
NVD link : CVE-2005-4025
Mitre link : CVE-2005-4025
JSON object : View
CWE
Products Affected
help_desk_reloaded
- free_help_desk