sitracker records
22 published records for vendor sitracker.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 2 · 9.1%
- Pre-auth RCE
- 4
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')3
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
- CWE-352 Cross-Site Request Forgery (CSRF)2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
22 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2007-5635No exploit | Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.sitracker · support incident tracker | Critical10.0 | — | 1.4% | Oct 23, 2007 |
31Monitor | CVE-2011-4337Proof of concept | Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to injsitracker · support incident tracker · CWE-94 | High7.5 | — | 2.4% | Jan 29, 2012 |
31Monitor | CVE-2011-3831No exploit | SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbitsitracker · support incident tracker · CWE-89 | High7.5 | — | 1.7% | Jan 29, 2012 |
30Monitor | CVE-2011-3833Weaponized | Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users sitracker · support incident tracker | Medium6.0 | — | 19.0% | Jan 29, 2012 |
30Monitor | CVE-2011-5071Proof of concept | Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL cositracker · support incident tracker · CWE-89 | High7.5 | — | 1.0% | Jan 29, 2012 |
30Monitor | CVE-2011-5072Proof of concept | Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL cositracker · support incident tracker · CWE-89 | High7.5 | — | 1.0% | Jan 29, 2012 |
27Monitor | CVE-2010-1596No exploit | Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication sitracker · support incident tracker · CWE-287 | Medium6.8 | — | 1.5% | Apr 28, 2010 |
27Monitor | CVE-2011-5074Proof of concept | Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijasitracker · support incident tracker · CWE-352 | Medium6.8 | — | 1.0% | Jan 29, 2012 |
27Monitor | CVE-2011-5068No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the sitracker · support incident tracker · CWE-352 | Medium6.8 | — | 0.7% | Jan 29, 2012 |
26Monitor | CVE-2011-3832No exploit | Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to executesitracker · support incident tracker · CWE-94 | Medium6.5 | — | 1.3% | Jan 29, 2012 |
25Monitor | CVE-2011-5069No exploit | Unrestricted file upload vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated usitracker · support incident tracker | Medium6.0 | — | 1.9% | Jan 29, 2012 |
24Monitor | CVE-2019-20223No exploit | In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVsitracker · support incident tracker · CWE-79 | Medium6.1 | — | 0.7% | Jan 2, 2020 |
24Monitor | CVE-2019-20220No exploit | In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.sitracker · support incident tracker · CWE-79 | Medium6.1 | — | 0.7% | Jan 2, 2020 |
24Monitor | CVE-2019-20221No exploit | In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS.sitracker · support incident tracker · CWE-79 | Medium6.1 | — | 0.7% | Jan 2, 2020 |
24Monitor | CVE-2019-20222No exploit | In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.sitracker · support incident tracker · CWE-79 | Medium6.1 | — | 0.7% | Jan 2, 2020 |
21Monitor | CVE-2011-3829Weaponized | ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the fisitracker · support incident tracker · CWE-200 | Medium4.0 | — | 17.1% | Jan 29, 2012 |
21Monitor | CVE-2011-5075Proof of concept | translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct sitracker · support incident tracker | Medium5.0 | — | 2.6% | Jan 29, 2012 |
18Monitor | CVE-2011-3830No exploit | Cross-site scripting (XSS) vulnerability in search.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to inject arbitrasitracker · support incident tracker · CWE-79 | Medium4.3 | — | 1.8% | Jan 29, 2012 |
17Monitor | CVE-2011-5073Proof of concept | Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbisitracker · support incident tracker · CWE-79 | Medium4.3 | — | 1.5% | Jan 29, 2012 |
17Monitor | CVE-2011-5070No exploit | Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject arbitrary wsitracker · support incident tracker · CWE-79 | Medium4.3 | — | 1.5% | Jan 29, 2012 |
17Monitor | CVE-2012-2235No exploit | Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary websitracker · support incident tracker · CWE-79 | Medium4.3 | — | 1.0% | May 27, 2012 |
16Monitor | CVE-2011-5067No exploit | move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via thesitracker · support incident tracker · CWE-200 | Medium4.0 | — | 0.9% | Jan 29, 2012 |
- CVE-2007-563540Plan
Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.
CriticalCVSS 10.0No exploitEPSS 1%sitracker · support incident trackerOct 23, 2007
- CVE-2011-433731Monitor
Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inj
HighCVSS 7.5Proof of conceptEPSS 2%sitracker · support incident trackerJan 29, 2012
- CVE-2011-383131Monitor
SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbit
HighCVSS 7.5No exploitEPSS 2%sitracker · support incident trackerJan 29, 2012
- CVE-2011-383330Monitor
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users
MediumCVSS 6.0WeaponizedEPSS 19%sitracker · support incident trackerJan 29, 2012
- CVE-2011-507130Monitor
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL co
HighCVSS 7.5Proof of conceptEPSS 1%sitracker · support incident trackerJan 29, 2012
- CVE-2011-507230Monitor
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL co
HighCVSS 7.5Proof of conceptEPSS 1%sitracker · support incident trackerJan 29, 2012
- CVE-2010-159627Monitor
Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication
MediumCVSS 6.8No exploitEPSS 2%sitracker · support incident trackerApr 28, 2010
- CVE-2011-507427Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hija
MediumCVSS 6.8Proof of conceptEPSS 1%sitracker · support incident trackerJan 29, 2012
- CVE-2011-506827Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the
MediumCVSS 6.8No exploitEPSS 1%sitracker · support incident trackerJan 29, 2012
- CVE-2011-383226Monitor
Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to execute
MediumCVSS 6.5No exploitEPSS 1%sitracker · support incident trackerJan 29, 2012
- CVE-2011-506925Monitor
Unrestricted file upload vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated u
MediumCVSS 6.0No exploitEPSS 2%sitracker · support incident trackerJan 29, 2012
- CVE-2019-2022324Monitor
In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CV
MediumCVSS 6.1No exploitEPSS 1%sitracker · support incident trackerJan 2, 2020
- CVE-2019-2022024Monitor
In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.
MediumCVSS 6.1No exploitEPSS 1%sitracker · support incident trackerJan 2, 2020
- CVE-2019-2022124Monitor
In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS.
MediumCVSS 6.1No exploitEPSS 1%sitracker · support incident trackerJan 2, 2020
- CVE-2019-2022224Monitor
In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.
MediumCVSS 6.1No exploitEPSS 1%sitracker · support incident trackerJan 2, 2020
- CVE-2011-382921Monitor
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the fi
MediumCVSS 4.0WeaponizedEPSS 17%sitracker · support incident trackerJan 29, 2012
- CVE-2011-507521Monitor
translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct
MediumCVSS 5.0Proof of conceptEPSS 3%sitracker · support incident trackerJan 29, 2012
- CVE-2011-383018Monitor
Cross-site scripting (XSS) vulnerability in search.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to inject arbitra
MediumCVSS 4.3No exploitEPSS 2%sitracker · support incident trackerJan 29, 2012
- CVE-2011-507317Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbi
MediumCVSS 4.3Proof of conceptEPSS 1%sitracker · support incident trackerJan 29, 2012
- CVE-2011-507017Monitor
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject arbitrary w
MediumCVSS 4.3No exploitEPSS 1%sitracker · support incident trackerJan 29, 2012
- CVE-2012-223517Monitor
Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary web
MediumCVSS 4.3No exploitEPSS 1%sitracker · support incident trackerMay 27, 2012
- CVE-2011-506716Monitor
move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the
MediumCVSS 4.0No exploitEPSS 1%sitracker · support incident trackerJan 29, 2012