S4E just found an informational finding from web application firewall (waf) detection scanner
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Jan 7, 2024

CVE-2015-2996 Scanner

Detects 'Local File Inclusion (LFI)' vulnerability in SysAid Help Desk affects v. before 15.2.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2015-2996
8.5
CVSS

Multiple directory traversal vulnerabilities in SysAid Help Desk before 15.2 allow remote attackers to (1) read arbitrary files via a .. (dot dot) in the fileName parameter to getGfiUpgradeFile or (2) cause a denial of service (CPU and memory consumption) via a .. (dot dot) in the fileName parameter to calculateRdsFileChecksum.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

SysAid Help Desk is a popular IT asset and service management solution that is used by many organizations for customer service, incident management, and IT support management. It allows users to automate tasks, track assets, and handle customer inquiries in a centralized system. SysAid provides a range of features such as ticket management, asset management, remote control, and many more, making IT support tasks more efficient and organized.

One major vulnerability that was detected in SysAid Help Desk is the CVE-2015-2996 vulnerability. This vulnerability allows remote attackers to exploit multiple directory traversal vulnerabilities in SysAid Help Desk before version 15.2. The vulnerability allows the attacker to read arbitrary files or cause a denial of service by inserting multiple.. (dot dot) characters in the fileName parameter of the getGfiUpgradeFile or calculateRdsFileChecksum API.

When exploited, CVE-2015-2996 can lead to serious consequences such as information disclosure, unauthorized access to sensitive data, and loss of critical information. The attacker can access confidential files, usernames, and passwords, leading to a data breach that can compromise the entire organization. Moreover, the attacker can cause a denial of service, which can disrupt the availability of the IT help desk system, causing significant business interruptions.

Thanks to the advanced features of the s4e.io platform, organizations can easily identify vulnerabilities in their digital assets. The platform provides advanced vulnerability scanning and penetration testing capabilities, enabling organizations to detect and remediate security risks quickly and efficiently. Moreover, the platform offers actionable insights and recommendations to improve the organization's security posture. Organizations can benefit from the comprehensive security solutions offered by the s4e.io platform to prevent cybersecurity threats and safeguard their digital assets.

 

REFERENCES

Solution Advice

To protect against CVE-2015-2996, organizations can take the following precautions:

  • Update the SysAid Help Desk solution to the latest version.
  • Restrict access to the SysAid Help Desk API by using a firewall or access controls.
  • Implement a web application firewall that can detect and block directory traversal attacks.
  • Monitor system logs and perform regular vulnerability assessments to detect any potential security threats.
  • Educate employees on cybersecurity preventive measures, such as using strong passwords and avoiding suspicious links or attachments.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2015-2996 scanner - Local File Inclusion (LFI) vulnerability in SysAid Help Desk | S4E