İçeriğe atla
Noroxi

osticket kayıtları

osticket üreticisine ait 13 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
6
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

13 kayıt
  • CVE-2017-15580
    44Planlayın

    osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats.

    KritikCVSS 9,8Kavram kanıtıEPSS %16

    osticket · osticket23 Eki 2017

  • CVE-2017-14396
    40Planlayın

    In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as

    KritikCVSS 9,8Kavram kanıtıEPSS %3

    osticket · osticket12 Eyl 2017

  • CVE-2004-0613
    33İzleyin

    osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP

    YüksekCVSS 7,5Kavram kanıtıEPSS %10

    osticket · osticket sts6 Ara 2004

  • CVE-2010-0605
    31İzleyin

    SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    osticket · osticket11 Şub 2010

  • CVE-2005-2154
    31İzleyin

    PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to includ

    YüksekCVSS 7,5Kavram kanıtıEPSS %2

    osticket · osticket sts6 Tem 2005

  • CVE-2005-1438
    30İzleyin

    PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir pa

    YüksekCVSS 7,5İstismar yokEPSS %1

    osticket · osticket3 May 2005

  • CVE-2005-2153
    30İzleyin

    SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands

    YüksekCVSS 7,5İstismar yokEPSS %1

    osticket · osticket sts6 Tem 2005

  • CVE-2005-1437
    30İzleyin

    Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admi

    YüksekCVSS 7,5İstismar yokEPSS %1

    osticket · osticket3 May 2005

  • CVE-2004-0614
    25İzleyin

    osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload

    OrtaCVSS 6,4İstismar yokEPSS %1

    osticket · osticket sts6 Ara 2004

  • CVE-2017-15362
    24İzleyin

    osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link,

    OrtaCVSS 6,1İstismar yokEPSS %1

    osticket · osticket15 Eki 2017

  • CVE-2025-45387
    21İzleyin

    osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.

    OrtaCVSS 5,4İstismar yokEPSS %0

    osticket · osticket2 Haz 2025

  • CVE-2006-6733
    17İzleyin

    Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web s

    OrtaCVSS 4,3Kavram kanıtıEPSS %2

    osticket · osticket sts26 Ara 2006

  • CVE-2010-0606
    14İzleyin

    Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitra

    DüşükCVSS 3,5İstismar yokEPSS %1

    osticket · osticket11 Şub 2010