Skip to content
Noroxi

sitracker records

22 published records for vendor sitracker.

All records

22 records
  • Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.

    CriticalCVSS 10.0No exploitEPSS 1%

    sitracker · support incident trackerOct 23, 2007

  • CVE-2011-4337
    31Monitor

    Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inj

    HighCVSS 7.5Proof of conceptEPSS 2%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-3831
    31Monitor

    SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbit

    HighCVSS 7.5No exploitEPSS 2%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-3833
    30Monitor

    Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users

    MediumCVSS 6.0WeaponizedEPSS 19%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-5071
    30Monitor

    Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL co

    HighCVSS 7.5Proof of conceptEPSS 1%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-5072
    30Monitor

    Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL co

    HighCVSS 7.5Proof of conceptEPSS 1%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2010-1596
    27Monitor

    Support Incident Tracker before 3.51, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication

    MediumCVSS 6.8No exploitEPSS 2%

    sitracker · support incident trackerApr 28, 2010

  • CVE-2011-5074
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hija

    MediumCVSS 6.8Proof of conceptEPSS 1%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-5068
    27Monitor

    Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to hijack the

    MediumCVSS 6.8No exploitEPSS 1%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-3832
    26Monitor

    Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to execute

    MediumCVSS 6.5No exploitEPSS 1%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-5069
    25Monitor

    Unrestricted file upload vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated u

    MediumCVSS 6.0No exploitEPSS 2%

    sitracker · support incident trackerJan 29, 2012

  • In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CV

    MediumCVSS 6.1No exploitEPSS 1%

    sitracker · support incident trackerJan 2, 2020

  • In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    sitracker · support incident trackerJan 2, 2020

  • In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    sitracker · support incident trackerJan 2, 2020

  • In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.

    MediumCVSS 6.1No exploitEPSS 1%

    sitracker · support incident trackerJan 2, 2020

  • CVE-2011-3829
    21Monitor

    ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the fi

    MediumCVSS 4.0WeaponizedEPSS 17%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-5075
    21Monitor

    translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct

    MediumCVSS 5.0Proof of conceptEPSS 3%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-3830
    18Monitor

    Cross-site scripting (XSS) vulnerability in search.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to inject arbitra

    MediumCVSS 4.3No exploitEPSS 2%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-5073
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbi

    MediumCVSS 4.3Proof of conceptEPSS 1%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2011-5070
    17Monitor

    Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) 3.65 allow remote attackers to inject arbitrary w

    MediumCVSS 4.3No exploitEPSS 1%

    sitracker · support incident trackerJan 29, 2012

  • CVE-2012-2235
    17Monitor

    Cross-site scripting (XSS) vulnerability in Support Incident Tracker (SiT!) 3.65 and earlier allows remote attackers to inject arbitrary web

    MediumCVSS 4.3No exploitEPSS 1%

    sitracker · support incident trackerMay 27, 2012

  • CVE-2011-5067
    16Monitor

    move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the

    MediumCVSS 4.0No exploitEPSS 1%

    sitracker · support incident trackerJan 29, 2012