CVE Vulnerabilities

CVE-2005-3925

Published: Nov 30, 2005 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple SQL injection vulnerabilities in Central Manchester CLC Helpdesk Issue Manager 0.9 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) detail[], (2) orderdir, and (3) orderby parameters to find.php, and the (4) id parameter to issue.php.

Affected Software

NameVendorStart VersionEnd Version
Helpdesk_issue_managerHelpdesk_issue_manager0.1 (including)0.1 (including)
Helpdesk_issue_managerHelpdesk_issue_manager0.2 (including)0.2 (including)
Helpdesk_issue_managerHelpdesk_issue_manager0.3 (including)0.3 (including)
Helpdesk_issue_managerHelpdesk_issue_manager0.4 (including)0.4 (including)
Helpdesk_issue_managerHelpdesk_issue_manager0.5 (including)0.5 (including)
Helpdesk_issue_managerHelpdesk_issue_manager0.6 (including)0.6 (including)
Helpdesk_issue_managerHelpdesk_issue_manager0.7 (including)0.7 (including)
Helpdesk_issue_managerHelpdesk_issue_manager0.8 (including)0.8 (including)
Helpdesk_issue_managerHelpdesk_issue_manager0.9 (including)0.9 (including)

References