Cerberus Helpdesk

Vendor:

First CVE: Jun 16, 2005 · Active for 21 years

9
Total CVEs
More Total CVEs than 88% of tracked products
3.0
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
5.3
Avg CVSS
Higher Avg CVSS than 13% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Cerberus Helpdesk over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 16, 2005
21 years ago
Most Recent CVE
Mar 6, 2009
6,353 days ago

CVE Severity & Scoring

Cerberus Helpdesk9 CVEs
All CVEs353,240 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network0 (0.0%)
Unknown9 (100.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low0 (0.0%)
High0 (0.0%)
Unknown9 (100.0%)
User Interaction
None0 (0.0%)
Unknown9 (100.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (100.0%)

Top CVEs

Signals from CVEs in this product scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parameter to attachment_send.php, (2) the $
Dec 20, 20057.529NOYES
rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain se
Oct 20, 20065.023NOYES
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbitrary web script or HTML via (1) the con
Feb 1, 20064.321NOYES
(1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk 3.2 Build 317, and possibly earlier, al
Sep 5, 20067.520NONO
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," poss
Mar 6, 20095.015NONO
attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id parameter.
Nov 5, 20055.015NONO
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.php, or (3) configuration.php, which lea
Jun 16, 20055.015NONO
Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML via the kb_ask parameter.
Dec 20, 20054.314NONO
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the (1) errorcode parameter to index.php or
Jun 16, 20054.314NONO

Exploit Exposure

Signals from CVEs in this product scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
33.3% of CVEs· 88th percentile

Social Chatter

Signals from CVEs in this product scope (9 CVEs).

Media Mentions

Signals from CVEs in this product scope (9 CVEs).

Top CNAs Publishing CVEs For Cerberus Helpdesk

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.2.115.02.7%01
3.217.51.8%00
2.7.1_development_release14.32.0%01
2.714.32.0%01
2.64925.92.3%01
2.6.115.01.6%00
2.525.01.4%00
2.415.01.6%00
2.315.01.6%00
2.215.01.6%00
2.115.01.6%00
2.015.01.6%00
0.97.324.71.4%00