Skip to main content

Vendor archive

cerberus CVEs

Beta · best-effort

13 CVEs tagged to vendor cerberus1 Critical, 2 High, 9 Medium, 1 Low, 0 Unrated.

CVE-2017-6880

Published Mar 17, 2017

Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST comma…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2007-5930

Published Nov 10, 2007

Cross-site scripting (XSS) vulnerability in the web interface in Cerberus FTP Server before 2.46 allows remote attackers to inject arbitrary web script or HTML via unspecified vec…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6366

Published Dec 7, 2006

Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, and 3.3 allows remote attackers to injec…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5428

Published Oct 20, 2006

rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain s…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-4539

Published Sep 5, 2006

(1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0509

Published Feb 1, 2006

Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the co…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-4427

Published Dec 20, 2005

Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2005-4428

Published Dec 20, 2005

Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-3502

Published Nov 5, 2005

attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1962

Published Jun 16, 2005

Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2005-1963

Published Jun 16, 2005

Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which le…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2003-1476

Published Dec 31, 2003

Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort
Showing 1-13 of 13 CVEsPage 1 of 1