Total vulnerabilities in the database
attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file number in a modified id parameter.
Software | From | Fixed in |
---|---|---|
headstart_solutions / deskpro | 2.0.0 | 2.0.0.x |
headstart_solutions / deskpro | 2.0.1 | 2.0.1.x |