Перейти к содержимому
Noroxi

Записи osticket

13 опубликованных записей вендора osticket.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
6
С записью об исправлении
0 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Записи по годам

  1. 17
  2. 25

Столбик: всего · тёмная часть: CISA KEV.

Повторяющиеся классы

Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.

CWE

Все записи

13 записей
  • CVE-2017-15580
    44В плане

    osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats.

    КритическаяCVSS 9,8Proof of conceptEPSS 16 %

    osticket · osticket23 окт. 2017 г.

  • CVE-2017-14396
    40В плане

    In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as

    КритическаяCVSS 9,8Proof of conceptEPSS 3 %

    osticket · osticket12 сент. 2017 г.

  • CVE-2004-0613
    33Наблюдать

    osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP

    ВысокаяCVSS 7,5Proof of conceptEPSS 10 %

    osticket · osticket sts6 дек. 2004 г.

  • CVE-2010-0605
    31Наблюдать

    SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    osticket · osticket11 февр. 2010 г.

  • CVE-2005-2154
    31Наблюдать

    PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to includ

    ВысокаяCVSS 7,5Proof of conceptEPSS 2 %

    osticket · osticket sts6 июл. 2005 г.

  • CVE-2005-1438
    30Наблюдать

    PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir pa

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    osticket · osticket3 мая 2005 г.

  • CVE-2005-2153
    30Наблюдать

    SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    osticket · osticket sts6 июл. 2005 г.

  • CVE-2005-1437
    30Наблюдать

    Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admi

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    osticket · osticket3 мая 2005 г.

  • CVE-2004-0614
    25Наблюдать

    osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload

    СредняяCVSS 6,4Эксплойта нетEPSS 1 %

    osticket · osticket sts6 дек. 2004 г.

  • CVE-2017-15362
    24Наблюдать

    osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link,

    СредняяCVSS 6,1Эксплойта нетEPSS 1 %

    osticket · osticket15 окт. 2017 г.

  • CVE-2025-45387
    21Наблюдать

    osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.

    СредняяCVSS 5,4Эксплойта нетEPSS 0 %

    osticket · osticket2 июн. 2025 г.

  • CVE-2006-6733
    17Наблюдать

    Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web s

    СредняяCVSS 4,3Proof of conceptEPSS 2 %

    osticket · osticket sts26 дек. 2006 г.

  • CVE-2010-0606
    14Наблюдать

    Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitra

    НизкаяCVSS 3,5Эксплойта нетEPSS 1 %

    osticket · osticket11 февр. 2010 г.