Enhancesoft

Osticket

47 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 2.48%
  • Veröffentlicht 30.12.2010 21:00:05
  • Zuletzt bearbeitet 10.07.2026 18:20:35

Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a different vector than CVE-2005-1439. NOTE: this issue has been disputed by a reliable third p...

Exploit
  • EPSS 0.87%
  • Veröffentlicht 11.02.2010 17:30:00
  • Zuletzt bearbeitet 10.07.2026 18:20:35

Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.

Exploit
  • EPSS 3.05%
  • Veröffentlicht 11.02.2010 17:30:00
  • Zuletzt bearbeitet 10.07.2026 18:20:35

SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.

Exploit
  • EPSS 5.17%
  • Veröffentlicht 08.07.2009 15:30:01
  • Zuletzt bearbeitet 10.07.2026 18:20:35

SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.

  • EPSS 1.43%
  • Veröffentlicht 19.10.2006 01:07:00
  • Zuletzt bearbeitet 10.07.2026 18:20:35

PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.

Exploit
  • EPSS 1.68%
  • Veröffentlicht 03.05.2005 04:00:00
  • Zuletzt bearbeitet 10.07.2026 18:20:35

Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php...

  • EPSS 1.72%
  • Veröffentlicht 03.05.2005 04:00:00
  • Zuletzt bearbeitet 10.07.2026 18:20:35

Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file parameter.