Skip to main content

Vendor/product archive

headstart_solutions / deskpro CVEs

Beta · best-effort

7 CVEs tagged to headstart_solutions / deskpro0 Critical, 2 High, 3 Medium, 2 Low, 0 Unrated.

CVE-2007-4412

Published Aug 18, 2007

Multiple cross-site scripting (XSS) vulnerabilities in Headstart Solutions DeskPRO 3.0.2 allow remote authenticated users to inject arbitrary web script or HTML via unspecified pa…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2007-4413

Published Aug 18, 2007

Direct static code injection vulnerability in admincp/user_help.php in Headstart Solutions DeskPRO 3.0.2 allows remote authenticated users to inject arbitrary PHP code into an uns…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6998

Published Feb 12, 2007

install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, which calls the phpinfo function.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6999

Published Feb 12, 2007

attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-7000

Published Feb 12, 2007

Headstart Solutions DeskPRO allows remote attackers to obtain the full path via direct requests to (1) email/mail.php, (2) includes/init.php, (3) certain files in includes/cron/,…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6973

Published Feb 7, 2007

Headstart Solutions DeskPRO does not require authentication for certain files and directories associated with administrative activities, which allows remote attackers to (1) reins…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6974

Published Feb 7, 2007

Headstart Solutions DeskPRO stores sensitive information under the web root with insufficient access control, which allows remote attackers to (1) list files in the includes/ dire…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1