Filtered by vendor Logicnow Subscriptions
Filtered by product Perldesk Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2004-1677 1 Logicnow 1 Perldesk 2025-04-03 N/A
pdesk.cgi in PerlDesk allows remote attackers to gain sensitive information via an invalid lang parameter, which includes pathname information in an error message.
CVE-2004-1678 1 Logicnow 1 Perldesk 2025-04-03 N/A
Directory traversal vulnerability in pdesk.cgi in PerlDesk allows remote attackers to read portions of arbitrary files and possibly execute arbitrary Perl modules via ".." sequences terminated by a %00 (null) character in the lang parameter, which can leak portions of the requested files if a compilation error message occurs.
CVE-2005-0343 1 Logicnow 1 Perldesk 2025-04-03 N/A
SQL injection vulnerability in PerlDesk 1.x allows remote attackers to inject arbitrary SQL commands via the view parameter.