Multiple cross-site scripting (XSS) vulnerabilities in Headstart Solutions DeskPRO 3.0.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified parameters to (1) techs.php, (2) ticket_category.php, (3) ticket_priority.php, (4) ticket_workflow.php, (5) ticket_escalate.php, (6) fields_ticket.php, (7) ticket_rules_web.php, (8) ticket_displayfields.php, (9) ticket_rules_mail.php, (10) fields_user.php, (11) fields_faq.php, and (12) user_help.php, in (a) admincp/ and (b) possibly a directory on the "User side."
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-08-18T21:00:00

Updated: 2024-08-07T14:53:55.954Z

Reserved: 2007-08-18T00:00:00

Link: CVE-2007-4412

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-08-18T21:17:00.000

Modified: 2018-10-15T21:35:14.340

Link: CVE-2007-4412

cve-icon Redhat

No data.