SQL injection vulnerability in one||zero (aka One or Zero) Helpdesk 1.4 rc4 allows remote attackers to modify arbitrary ticket number descriptions via the sg parameter.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/7609 | vdb entry |
http://archives.neohapsis.com/archives/vulnwatch/2003-q2/0070.html | mailing list exploit patch vendor advisory |
http://marc.info/?l=bugtraq&m=105302025601231&w=2 | mailing list |