Vulnerabilities (CVE)

Filtered by vendor Logicnow Subscribe
Filtered by product Perldesk
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2005-0343 1 Logicnow 1 Perldesk 2023-12-10 7.5 HIGH N/A
SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter.
CVE-2004-1678 1 Logicnow 1 Perldesk 2023-12-10 5.0 MEDIUM N/A
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.
CVE-2004-1677 1 Logicnow 1 Perldesk 2023-12-10 5.0 MEDIUM N/A
pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.