Osticket

Osticket

16 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.21%
  • Veröffentlicht 16.10.2017 01:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, inject...

  • EPSS 2.92%
  • Veröffentlicht 12.09.2017 21:29:00
  • Zuletzt bearbeitet 13.05.2026 00:24:29

In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

Exploit
  • EPSS 3.05%
  • Veröffentlicht 11.02.2010 17:30:00
  • Zuletzt bearbeitet 10.07.2026 18:20:35

SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.

Exploit
  • EPSS 0.87%
  • Veröffentlicht 11.02.2010 17:30:00
  • Zuletzt bearbeitet 10.07.2026 18:20:35

Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.

Exploit
  • EPSS 1.32%
  • Veröffentlicht 03.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:13:02

Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admin.php or (2) cat parameter to view.php.

  • EPSS 1.49%
  • Veröffentlicht 03.05.2005 04:00:00
  • Zuletzt bearbeitet 16.06.2026 22:13:02

PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.