CVE-2015-2999

SysAid Help Desk <15.2 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2015-2999.

AI-analyzed exploit summary This document provides a detailed technical analysis of multiple vulnerabilities in SysAid Help Desk 14.4, including SQL injection (CVE-2015-2999), file upload, arbitrary file download, and path disclosure. It includes proof-of-concept requests and explanations of exploitation constraints.

Description

Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the (1) groupFilter parameter in an AssetDetails report to /genericreport, customSQL parameter in a (2) TopAdministratorsByAverageTimer report or an (3) ActiveRequests report to /genericreport, (4) dir parameter to HelpDesk.jsp, or (5) grantSQL parameter to RFCGantt.jsp.

Exploits (1)

exploitdb WRITEUP
webappshardware
https://www.exploit-db.com/exploits/43885

This document provides a detailed technical analysis of multiple vulnerabilities in SysAid Help Desk 14.4, including SQL injection (CVE-2015-2999), file upload, arbitrary file download, and path disclosure. It includes proof-of-concept requests and explanations of exploitation constraints.

Classification
Writeup 100%
Attack Type
Sqli | Rce | Info Leak | Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: SysAid Help Desk 14.4
No auth needed
Prerequisites: Network access to the target · Java 7u25 or lower for unauthenticated file upload
devstral-2 · analyzed Feb 19, 2026 Full analysis →

References (5)

Core 5
Core References
Exploit mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2015/Jun/8
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/535679/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/75038

Scores

EPSS 0.0181
EPSS Percentile 75.8%

Details

CWE
CWE-89
Status published
Products (1)
sysaid/sysaid < 15.1
Published Jun 08, 2015
Tracked Since Feb 18, 2026