Cerberus records
14 published records for vendor cerberus.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer1
- CWE-287 Improper Authentication1
- CWE-400 Uncontrolled Resource Consumption1
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
14 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
43Plan | CVE-2017-6880Proof of concept | Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecicerberus · cerberus ftp server · CWE-119 | Critical9.8 | — | 14.3% | Mar 17, 2017 |
31Monitor | CVE-2005-4427Proof of concept | Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id parcerberus · cerberus helpdesk | High7.5 | — | 3.2% | Dec 20, 2005 |
31Monitor | CVE-2006-4539No exploit | (1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdeskcerberus · cerberus helpdesk | High7.5 | — | 1.8% | Sep 5, 2006 |
30Monitor | CVE-2024-5052No exploit | Resource consumption vulnerability in Cerberus FTP Enterprisecerberus ftp enterprise · cerberus ftp enterprise · CWE-400 | High7.5 | — | 0.4% | May 17, 2024 |
28Monitor | CVE-2006-6366Proof of concept | Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, acerberus · helpdesk | Medium6.8 | — | 1.8% | Dec 7, 2006 |
21Monitor | CVE-2006-5428Proof of concept | rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackecerberus · cerberus helpdesk | Medium5.0 | — | 2.8% | Oct 20, 2006 |
20Monitor | CVE-2005-3502No exploit | attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id paramcerberus · cerberus helpdesk | Medium5.0 | — | 1.5% | Nov 5, 2005 |
20Monitor | CVE-2005-1963No exploit | Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.cerberus · cerberus helpdesk | Medium5.0 | — | 1.5% | Jun 16, 2005 |
20Monitor | CVE-2008-6440No exploit | Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ...cerberus · cerberus helpdesk · CWE-287 | Medium5.0 | — | 1.2% | Mar 6, 2009 |
18Monitor | CVE-2006-0509Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbicerberus · cerberus helpdesk | Medium4.3 | — | 2.0% | Feb 1, 2006 |
17Monitor | CVE-2005-4428No exploit | Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML vicerberus · cerberus helpdesk | Medium4.3 | — | 1.3% | Dec 20, 2005 |
17Monitor | CVE-2005-1962No exploit | Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the cerberus · cerberus helpdesk | Medium4.3 | — | 1.3% | Jun 16, 2005 |
17Monitor | CVE-2007-5930No exploit | Cross-site scripting (XSS) vulnerability in the web interface in Cerberus FTP Server before 2.46 allows remote attackers to inject arbitrarycerberus · ftp server · CWE-79 | Medium4.3 | — | 1.2% | Nov 10, 2007 |
8Monitor | CVE-2003-1476No exploit | Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.cerberus · ftp server | Low2.1 | — | 0.3% | Dec 31, 2003 |
- CVE-2017-688043Plan
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspeci
CriticalCVSS 9.8Proof of conceptEPSS 14%cerberus · cerberus ftp serverMar 17, 2017
- CVE-2005-442731Monitor
Multiple SQL injection vulnerabilities in Cerberus Helpdesk allow remote attackers to execute arbitrary SQL commands via the (1) file_id par
HighCVSS 7.5Proof of conceptEPSS 3%cerberus · cerberus helpdeskDec 20, 2005
- CVE-2006-453931Monitor
(1) includes/widgets/module_company_tickets.php and (2) includes/widgets/module_track_tickets.php Client Support Center in Cerberus Helpdesk
HighCVSS 7.5No exploitEPSS 2%cerberus · cerberus helpdeskSep 5, 2006
- CVE-2024-505230Monitor
Resource consumption vulnerability in Cerberus FTP Enterprise
HighCVSS 7.5No exploitEPSS 0%cerberus ftp enterprise · cerberus ftp enterpriseMay 17, 2024
- CVE-2006-636628Monitor
Cross-site scripting (XSS) vulnerability in includes/elements/spellcheck/spellwin.php in Cerberus Helpdesk 0.97.3, 2.0 through 2.7, 3.2.1, a
MediumCVSS 6.8Proof of conceptEPSS 2%cerberus · helpdeskDec 7, 2006
- CVE-2006-542821Monitor
rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attacke
MediumCVSS 5.0Proof of conceptEPSS 3%cerberus · cerberus helpdeskOct 20, 2006
- CVE-2005-350220Monitor
attachment_send.php in Cerberus Helpdesk allows remote attackers to view attachments and tickets of other users via a modified file_id param
MediumCVSS 5.0No exploitEPSS 2%cerberus · cerberus helpdeskNov 5, 2005
- CVE-2005-196320Monitor
Cerberus Helpdesk 0.97.3 allows remote attackers to obtain sensitive information via certain requests to (1) reports.php, (2) knowledgebase.
MediumCVSS 5.0No exploitEPSS 2%cerberus · cerberus helpdeskJun 16, 2005
- CVE-2008-644020Monitor
Cerberus Helpdesk before 4.0 (Build 600) allows remote attackers to obtain sensitive information via direct requests for "controllers ...
MediumCVSS 5.0No exploitEPSS 1%cerberus · cerberus helpdeskMar 6, 2009
- CVE-2006-050918Monitor
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote attackers to inject arbi
MediumCVSS 4.3Proof of conceptEPSS 2%cerberus · cerberus helpdeskFeb 1, 2006
- CVE-2005-442817Monitor
Cross-site scripting (XSS) vulnerability in index.php in Cerberus Helpdesk allows remote attackers to inject arbitrary web script or HTML vi
MediumCVSS 4.3No exploitEPSS 1%cerberus · cerberus helpdeskDec 20, 2005
- CVE-2005-196217Monitor
Cross-site scripting (XSS) vulnerability in Cerberus Helpdesk 0.97.3 allows remote attackers to inject arbitrary web script or HTML via the
MediumCVSS 4.3No exploitEPSS 1%cerberus · cerberus helpdeskJun 16, 2005
- CVE-2007-593017Monitor
Cross-site scripting (XSS) vulnerability in the web interface in Cerberus FTP Server before 2.46 allows remote attackers to inject arbitrary
MediumCVSS 4.3No exploitEPSS 1%cerberus · ftp serverNov 10, 2007
- CVE-2003-14768Monitor
Cerberus FTP Server 2.1 stores usernames and passwords in plaintext, which could allow local users to gain access.
LowCVSS 2.1No exploitEPSS 0%cerberus · ftp serverDec 31, 2003