Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which leaks the information in a PHP error message.
Link | Tags |
---|---|
http://www.wgmdev.com/jira/browse/CERB-170 | |
http://forum.cerberusweb.com/showthread.php?threadid=5162&goto=newpost | exploit |
http://securitytracker.com/id?1014128 | vdb entry |
http://echo.or.id/adv/adv15-theday-2005.txt | exploit |
http://secunia.com/advisories/15641 | third party advisory |