- EPSS 2.48%
- Veröffentlicht 30.12.2010 21:00:05
- Zuletzt bearbeitet 10.07.2026 18:20:35
Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a different vector than CVE-2005-1439. NOTE: this issue has been disputed by a reliable third p...
CVE-2010-0606
- EPSS 0.87%
- Veröffentlicht 11.02.2010 17:30:00
- Zuletzt bearbeitet 10.07.2026 18:20:35
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.
CVE-2010-0605
- EPSS 3.05%
- Veröffentlicht 11.02.2010 17:30:00
- Zuletzt bearbeitet 10.07.2026 18:20:35
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.
CVE-2009-2361
- EPSS 5.17%
- Veröffentlicht 08.07.2009 15:30:01
- Zuletzt bearbeitet 10.07.2026 18:20:35
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.
CVE-2006-5407
- EPSS 1.43%
- Veröffentlicht 19.10.2006 01:07:00
- Zuletzt bearbeitet 10.07.2026 18:20:35
PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.
CVE-2005-1436
- EPSS 1.68%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 10.07.2026 18:20:35
Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php...
CVE-2005-1439
- EPSS 1.72%
- Veröffentlicht 03.05.2005 04:00:00
- Zuletzt bearbeitet 10.07.2026 18:20:35
Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.