CVE-2015-2999

SysAid Help Desk <15.2 - SQL Injection

Title source: llm

Description

Multiple SQL injection vulnerabilities in SysAid Help Desk before 15.2 allow remote administrators to execute arbitrary SQL commands via the (1) groupFilter parameter in an AssetDetails report to /genericreport, customSQL parameter in a (2) TopAdministratorsByAverageTimer report or an (3) ActiveRequests report to /genericreport, (4) dir parameter to HelpDesk.jsp, or (5) grantSQL parameter to RFCGantt.jsp.

Exploits (1)

exploitdb WRITEUP
webappshardware
https://www.exploit-db.com/exploits/43885

Scores

EPSS 0.0102
EPSS Percentile 77.3%

Details

CWE
CWE-89
Status published
Products (1)
sysaid/sysaid < 15.1
Published Jun 08, 2015
Tracked Since Feb 18, 2026