ExoPHPdesk user profile XSS / profile SQL injection
http://exoscripts.com/exohelpdesk
You can inject script code into the website area where you create profile.
Cookies are in place making an XSS more than possible.
http://example.com/helpdesk/index.php?fn=profile&s=&user=admin' sql here
SQL injection in the profile area is possible if you choose a bad input.
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.