CVE-2006-6158
Ace Helpdesk 2.31 - Cross-Site Scripting via Ticket View and Ticket Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2006-6158. PoCs published by SwEET-DeViL.
AI-analyzed exploit summary The provided text describes multiple XSS vulnerabilities in InverseFlow Help Desk version 2.31, detailing specific URLs where arbitrary script code can be executed. It also mentions that other versions and related software may be affected.
Description
Multiple cross-site scripting (XSS) vulnerabilities in (a) PMOS Help Desk 2.4, formerly (b) InverseFlow Help Desk 2.31 and also sold as (c) Ace Helpdesk 2.31, allow remote attackers to inject arbitrary web script or HTML via the (1) id or email parameter to ticketview.php, or (2) the email parameter to ticket.php.
Exploits (2)
The provided text describes multiple XSS vulnerabilities in InverseFlow Help Desk version 2.31, detailing specific URLs where arbitrary script code can be executed. It also mentions that other versions and related software may be affected.
The provided text describes a cross-site scripting (XSS) vulnerability in InverseFlow Help Desk version 2.31, where arbitrary script code can be executed via the 'email' parameter in the 'ticket.php' file. The vulnerability may also affect other versions and related products like Ace Helpdesk and PMOS Helpdesk.