osticket records
13 published records for vendor osticket.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 6
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
The weakness classes this vendor ships most often: where to look.
CWEAll records
13 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
44Plan | CVE-2017-15580Proof of concept | osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats.osticket · osticket · CWE-434 | Critical9.8 | — | 15.6% | Oct 23, 2017 |
40Plan | CVE-2017-14396Proof of concept | In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as osticket · osticket · CWE-89 | Critical9.8 | — | 2.9% | Sep 12, 2017 |
33Monitor | CVE-2004-0613Proof of concept | osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHPosticket · osticket sts | High7.5 | — | 9.9% | Dec 6, 2004 |
31Monitor | CVE-2010-0605Proof of concept | SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to osticket · osticket · CWE-89 | High7.5 | — | 3.0% | Feb 11, 2010 |
31Monitor | CVE-2005-2154Proof of concept | PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to includosticket · osticket sts | High7.5 | — | 2.4% | Jul 6, 2005 |
30Monitor | CVE-2005-1438No exploit | PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir paosticket · osticket | High7.5 | — | 1.5% | May 3, 2005 |
30Monitor | CVE-2005-2153No exploit | SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commandsosticket · osticket sts | High7.5 | — | 1.3% | Jul 6, 2005 |
30Monitor | CVE-2005-1437No exploit | Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admiosticket · osticket | High7.5 | — | 1.3% | May 3, 2005 |
25Monitor | CVE-2004-0614No exploit | osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload osticket · osticket sts | Medium6.4 | — | 1.2% | Dec 6, 2004 |
24Monitor | CVE-2017-15362No exploit | osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, osticket · osticket · CWE-79 | Medium6.1 | — | 1.2% | Oct 15, 2017 |
21Monitor | CVE-2025-45387No exploit | osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.osticket · osticket · CWE-79 | Medium5.4 | — | 0.2% | Jun 2, 2025 |
17Monitor | CVE-2006-6733Proof of concept | Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web sosticket · osticket sts · CWE-79 | Medium4.3 | — | 1.6% | Dec 26, 2006 |
14Monitor | CVE-2010-0606No exploit | Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitraosticket · osticket · CWE-79 | Low3.5 | — | 0.9% | Feb 11, 2010 |
- CVE-2017-1558044Plan
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats.
CriticalCVSS 9.8Proof of conceptEPSS 16%osticket · osticketOct 23, 2017
- CVE-2017-1439640Plan
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as
CriticalCVSS 9.8Proof of conceptEPSS 3%osticket · osticketSep 12, 2017
- CVE-2004-061333Monitor
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP
HighCVSS 7.5Proof of conceptEPSS 10%osticket · osticket stsDec 6, 2004
- CVE-2010-060531Monitor
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to
HighCVSS 7.5Proof of conceptEPSS 3%osticket · osticketFeb 11, 2010
- CVE-2005-215431Monitor
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to includ
HighCVSS 7.5Proof of conceptEPSS 2%osticket · osticket stsJul 6, 2005
- CVE-2005-143830Monitor
PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir pa
HighCVSS 7.5No exploitEPSS 1%osticket · osticketMay 3, 2005
- CVE-2005-215330Monitor
SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands
HighCVSS 7.5No exploitEPSS 1%osticket · osticket stsJul 6, 2005
- CVE-2005-143730Monitor
Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admi
HighCVSS 7.5No exploitEPSS 1%osticket · osticketMay 3, 2005
- CVE-2004-061425Monitor
osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload
MediumCVSS 6.4No exploitEPSS 1%osticket · osticket stsDec 6, 2004
- CVE-2017-1536224Monitor
osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link,
MediumCVSS 6.1No exploitEPSS 1%osticket · osticketOct 15, 2017
- CVE-2025-4538721Monitor
osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.
MediumCVSS 5.4No exploitEPSS 0%osticket · osticketJun 2, 2025
- CVE-2006-673317Monitor
Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web s
MediumCVSS 4.3Proof of conceptEPSS 2%osticket · osticket stsDec 26, 2006
- CVE-2010-060614Monitor
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitra
LowCVSS 3.5No exploitEPSS 1%osticket · osticketFeb 11, 2010