Записи osticket
13 опубликованных записей вендора osticket.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 6
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
13 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2017-15580Proof of concept | osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats.osticket · osticket · CWE-434 | Критическая9,8 | — | 15,6 % | 23 окт. 2017 г. |
40В плане | CVE-2017-14396Proof of concept | In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as osticket · osticket · CWE-89 | Критическая9,8 | — | 2,9 % | 12 сент. 2017 г. |
33Наблюдать | CVE-2004-0613Proof of concept | osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHPosticket · osticket sts | Высокая7,5 | — | 9,9 % | 6 дек. 2004 г. |
31Наблюдать | CVE-2010-0605Proof of concept | SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to osticket · osticket · CWE-89 | Высокая7,5 | — | 3,0 % | 11 февр. 2010 г. |
31Наблюдать | CVE-2005-2154Proof of concept | PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to includosticket · osticket sts | Высокая7,5 | — | 2,4 % | 6 июл. 2005 г. |
30Наблюдать | CVE-2005-1438Эксплойта нет | PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir paosticket · osticket | Высокая7,5 | — | 1,5 % | 3 мая 2005 г. |
30Наблюдать | CVE-2005-2153Эксплойта нет | SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commandsosticket · osticket sts | Высокая7,5 | — | 1,3 % | 6 июл. 2005 г. |
30Наблюдать | CVE-2005-1437Эксплойта нет | Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admiosticket · osticket | Высокая7,5 | — | 1,3 % | 3 мая 2005 г. |
25Наблюдать | CVE-2004-0614Эксплойта нет | osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload osticket · osticket sts | Средняя6,4 | — | 1,2 % | 6 дек. 2004 г. |
24Наблюдать | CVE-2017-15362Эксплойта нет | osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, osticket · osticket · CWE-79 | Средняя6,1 | — | 1,2 % | 15 окт. 2017 г. |
21Наблюдать | CVE-2025-45387Эксплойта нет | osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.osticket · osticket · CWE-79 | Средняя5,4 | — | 0,2 % | 2 июн. 2025 г. |
17Наблюдать | CVE-2006-6733Proof of concept | Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web sosticket · osticket sts · CWE-79 | Средняя4,3 | — | 1,6 % | 26 дек. 2006 г. |
14Наблюдать | CVE-2010-0606Эксплойта нет | Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitraosticket · osticket · CWE-79 | Низкая3,5 | — | 0,9 % | 11 февр. 2010 г. |
- CVE-2017-1558044В плане
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats.
КритическаяCVSS 9,8Proof of conceptEPSS 16 %osticket · osticket23 окт. 2017 г.
- CVE-2017-1439640В плане
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as
КритическаяCVSS 9,8Proof of conceptEPSS 3 %osticket · osticket12 сент. 2017 г.
- CVE-2004-061333Наблюдать
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP
ВысокаяCVSS 7,5Proof of conceptEPSS 10 %osticket · osticket sts6 дек. 2004 г.
- CVE-2010-060531Наблюдать
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %osticket · osticket11 февр. 2010 г.
- CVE-2005-215431Наблюдать
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to includ
ВысокаяCVSS 7,5Proof of conceptEPSS 2 %osticket · osticket sts6 июл. 2005 г.
- CVE-2005-143830Наблюдать
PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir pa
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %osticket · osticket3 мая 2005 г.
- CVE-2005-215330Наблюдать
SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %osticket · osticket sts6 июл. 2005 г.
- CVE-2005-143730Наблюдать
Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admi
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %osticket · osticket3 мая 2005 г.
- CVE-2004-061425Наблюдать
osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload
СредняяCVSS 6,4Эксплойта нетEPSS 1 %osticket · osticket sts6 дек. 2004 г.
- CVE-2017-1536224Наблюдать
osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link,
СредняяCVSS 6,1Эксплойта нетEPSS 1 %osticket · osticket15 окт. 2017 г.
- CVE-2025-4538721Наблюдать
osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.
СредняяCVSS 5,4Эксплойта нетEPSS 0 %osticket · osticket2 июн. 2025 г.
- CVE-2006-673317Наблюдать
Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web s
СредняяCVSS 4,3Proof of conceptEPSS 2 %osticket · osticket sts26 дек. 2006 г.
- CVE-2010-060614Наблюдать
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitra
НизкаяCVSS 3,5Эксплойта нетEPSS 1 %osticket · osticket11 февр. 2010 г.