Vulnerabilities
Vulnerable Software
install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a q=phpinfo QUERY_STRING, which calls the phpinfo function.
CVSS Score
5.0
EPSS Score
0.011
Published
2007-02-12
attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.
CVSS Score
4.3
EPSS Score
0.01
Published
2007-02-12
Headstart Solutions DeskPRO allows remote attackers to obtain the full path via direct requests to (1) email/mail.php, (2) includes/init.php, (3) certain files in includes/cron/, and (4) jpgraph.php, (5) jpgraph_bar.php, (6) jpgraph_pie.php, and (7) jpgraph_pie3d.php in includes/graph/, which leaks the path in error messages.
CVSS Score
5.0
EPSS Score
0.011
Published
2007-02-12


Contact Us

Shodan ® - All rights reserved