form.php in PMOS Help Desk 2.4 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to conduct eval injection attacks and execute arbitrary PHP code via the options array parameter.
References
Configurations
Information
Published : 2007-12-27 16:46
Updated : 2017-09-28 18:29
NVD link : CVE-2007-6550
Mitre link : CVE-2007-6550
JSON object : View
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
Products Affected
pmos_helpdesk
- pmos_helpdesk