Skip to content
Noroxi

osticket records

13 published records for vendor osticket.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
6
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

13 records
  • osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats.

    CriticalCVSS 9.8Proof of conceptEPSS 16%

    osticket · osticketOct 23, 2017

  • In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    osticket · osticketSep 12, 2017

  • CVE-2004-0613
    33Monitor

    osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP

    HighCVSS 7.5Proof of conceptEPSS 10%

    osticket · osticket stsDec 6, 2004

  • CVE-2010-0605
    31Monitor

    SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to

    HighCVSS 7.5Proof of conceptEPSS 3%

    osticket · osticketFeb 11, 2010

  • CVE-2005-2154
    31Monitor

    PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to includ

    HighCVSS 7.5Proof of conceptEPSS 2%

    osticket · osticket stsJul 6, 2005

  • CVE-2005-1438
    30Monitor

    PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir pa

    HighCVSS 7.5No exploitEPSS 1%

    osticket · osticketMay 3, 2005

  • CVE-2005-2153
    30Monitor

    SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands

    HighCVSS 7.5No exploitEPSS 1%

    osticket · osticket stsJul 6, 2005

  • CVE-2005-1437
    30Monitor

    Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admi

    HighCVSS 7.5No exploitEPSS 1%

    osticket · osticketMay 3, 2005

  • CVE-2004-0614
    25Monitor

    osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload

    MediumCVSS 6.4No exploitEPSS 1%

    osticket · osticket stsDec 6, 2004

  • osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link,

    MediumCVSS 6.1No exploitEPSS 1%

    osticket · osticketOct 15, 2017

  • osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.

    MediumCVSS 5.4No exploitEPSS 0%

    osticket · osticketJun 2, 2025

  • CVE-2006-6733
    17Monitor

    Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web s

    MediumCVSS 4.3Proof of conceptEPSS 2%

    osticket · osticket stsDec 26, 2006

  • CVE-2010-0606
    14Monitor

    Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitra

    LowCVSS 3.5No exploitEPSS 1%

    osticket · osticketFeb 11, 2010