>> Cerberus Helpdesk "rpc.php" Security Bypass and Information Disclosure Issue
Title : Cerberus Helpdesk "rpc.php" Security Bypass and Information Disclosure Issue VUPEN ID : VUPEN/ADV-2006-4089 CVE ID : CVE-2006-5428
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-18
Technical Description
A vulnerability has been identified in Cerberus Helpdesk, which could be exploited by attackers to gain knowledge of sensitive information. This flaw is due to a design error where the "rpc.php" script is accessible without requiring authentication, which could be exploited by attackers to disclose certain data related to tickets (e.g. a requester's email address).