OneOrZero Helpdesk < 220.127.116.11 index.php id Parameter SQL Injection
High Nessus Network Monitor Plugin ID 3492
SynopsisThe remote host is vulnerable to a SQL Injection attack.
DescriptionThe remote host is running OneOrZero, an open-source helpdesk application. This version of OneOrZero is vulnerable to a SQL Injection flaw. An attacker exploiting this flaw would be able to execute arbitrary SQL commands on the backend SQL server. This can lead to loss of confidentiality, integrity and availability.
SolutionUpgrade to version 18.104.22.168 or higher.