9.8

CVE-2017-15580

Exploit
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OsticketOsticket Version1.10.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 15.98% 0.965
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-434 Unrestricted Upload of File with Dangerous Type

The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

http://0day.today/exploits/28864
Third Party Advisory
http://nakedsecurity.com/cve/CVE-2017-15580/
Third Party Advisory
https://becomepentester.blogspot.com/2017/10/osTicket-File-Upload-Restrictions-Bypassed-CVE-2017-15580.html
Third Party Advisory
Exploit
https://cxsecurity.com/issue/WLB-2017100187
Third Party Advisory
Exploit
https://packetstormsecurity.com/files/144747/osticket1101-shell.txt
Third Party Advisory
Exploit
VDB Entry
https://www.cyber-security.ro/blog/2017/10/25/osticket-1-10-1-shell-upload/
Broken Link
https://www.exploit-db.com/exploits/45169/
Third Party Advisory
Exploit
VDB Entry