CVE-2019-20223
- EPSS 0.33%
- Veröffentlicht 02.01.2020 14:16:36
- Zuletzt bearbeitet 21.11.2024 04:38:14
In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVE-2012-2235.
CVE-2019-20222
- EPSS 0.33%
- Veröffentlicht 02.01.2020 14:16:36
- Zuletzt bearbeitet 21.11.2024 04:38:14
In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.
CVE-2019-20221
- EPSS 0.33%
- Veröffentlicht 02.01.2020 14:16:36
- Zuletzt bearbeitet 21.11.2024 04:38:14
In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page.
CVE-2019-20220
- EPSS 0.33%
- Veröffentlicht 02.01.2020 14:16:36
- Zuletzt bearbeitet 21.11.2024 04:38:14
In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.
CVE-2012-2235
- EPSS 0.23%
- Veröffentlicht 27.05.2012 19:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary web script or HTML via the id parameter to index.php, which is not properly handled in an error message.
- EPSS 5.03%
- Veröffentlicht 29.01.2012 11:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct request using the save action, which reveals the installation path.
CVE-2011-5074
- EPSS 0.2%
- Veröffentlicht 29.01.2012 11:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators for requests that change administrator email, add a new administrator,...
CVE-2011-5073
- EPSS 0.51%
- Veröffentlicht 29.01.2012 11:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbitrary web script or HTML via the (1) mode parameter to contact_support.php; (2) contractid parameter to contra...
CVE-2011-5072
- EPSS 0.32%
- Veröffentlicht 29.01.2012 11:55:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to portal/kb.php; (2) contractid parameter to contract_add_service.php; (3)...
CVE-2011-4337
- EPSS 3.56%
- Veröffentlicht 29.01.2012 11:55:01
- Zuletzt bearbeitet 11.04.2025 00:51:21
Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inject arbitrary PHP code into an executable language file in the i18n directory via the lang variable.