CVE-2017-15362
- EPSS 1.21%
- Veröffentlicht 16.10.2017 01:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, aka XSS. Session ID and data theft may follow as well as the possibility of bypassing CSRF protections, inject...
CVE-2017-14396
- EPSS 2.92%
- Veröffentlicht 12.09.2017 21:29:00
- Zuletzt bearbeitet 13.05.2026 00:24:29
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.
CVE-2010-0605
- EPSS 3.05%
- Veröffentlicht 11.02.2010 17:30:00
- Zuletzt bearbeitet 10.07.2026 18:20:35
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.
CVE-2010-0606
- EPSS 0.87%
- Veröffentlicht 11.02.2010 17:30:00
- Zuletzt bearbeitet 10.07.2026 18:20:35
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.
CVE-2005-1437
- EPSS 1.32%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:13:02
Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admin.php or (2) cat parameter to view.php.
CVE-2005-1438
- EPSS 1.49%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 16.06.2026 22:13:02
PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir parameter.