CVE-2008-6440

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
06/03/2009
Last modified:
09/04/2025

Description

Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ... that aren't standard helpdesk pages," possibly involving the (1) /display and (2) /kb URIs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cerberus:cerberus_helpdesk:2.5:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:*:*:*:*:*:*:*:* 3.3 (including)
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:0.97.3:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:2.0:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:2.1:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:2.2:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:2.3:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:2.4:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:2.6.1:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:2.7:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:2.7.1:development_release:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:2.649:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:3.2:*:*:*:*:*:*:*
cpe:2.3:a:webgroupmedia:cerberus_helpdesk:3.2.1:*:*:*:*:*:*:*