osticket kayıtları
osticket üreticisine ait 13 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 6
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
13 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2017-15580Kavram kanıtı | osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats.osticket · osticket · CWE-434 | Kritik9,8 | — | %15,6 | 23 Eki 2017 |
40Planlayın | CVE-2017-14396Kavram kanıtı | In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as osticket · osticket · CWE-89 | Kritik9,8 | — | %2,9 | 12 Eyl 2017 |
33İzleyin | CVE-2004-0613Kavram kanıtı | osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHPosticket · osticket sts | Yüksek7,5 | — | %9,9 | 6 Ara 2004 |
31İzleyin | CVE-2010-0605Kavram kanıtı | SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to osticket · osticket · CWE-89 | Yüksek7,5 | — | %3,0 | 11 Şub 2010 |
31İzleyin | CVE-2005-2154Kavram kanıtı | PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to includosticket · osticket sts | Yüksek7,5 | — | %2,4 | 6 Tem 2005 |
30İzleyin | CVE-2005-1438İstismar yok | PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir paosticket · osticket | Yüksek7,5 | — | %1,5 | 3 May 2005 |
30İzleyin | CVE-2005-2153İstismar yok | SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commandsosticket · osticket sts | Yüksek7,5 | — | %1,3 | 6 Tem 2005 |
30İzleyin | CVE-2005-1437İstismar yok | Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admiosticket · osticket | Yüksek7,5 | — | %1,3 | 3 May 2005 |
25İzleyin | CVE-2004-0614İstismar yok | osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload osticket · osticket sts | Orta6,4 | — | %1,2 | 6 Ara 2004 |
24İzleyin | CVE-2017-15362İstismar yok | osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link, osticket · osticket · CWE-79 | Orta6,1 | — | %1,2 | 15 Eki 2017 |
21İzleyin | CVE-2025-45387İstismar yok | osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.osticket · osticket · CWE-79 | Orta5,4 | — | %0,2 | 2 Haz 2025 |
17İzleyin | CVE-2006-6733Kavram kanıtı | Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web sosticket · osticket sts · CWE-79 | Orta4,3 | — | %1,6 | 26 Ara 2006 |
14İzleyin | CVE-2010-0606İstismar yok | Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitraosticket · osticket · CWE-79 | Düşük3,5 | — | %0,9 | 11 Şub 2010 |
- CVE-2017-1558044Planlayın
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats.
KritikCVSS 9,8Kavram kanıtıEPSS %16osticket · osticket23 Eki 2017
- CVE-2017-1439640Planlayın
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as
KritikCVSS 9,8Kavram kanıtıEPSS %3osticket · osticket12 Eyl 2017
- CVE-2004-061333İzleyin
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP
YüksekCVSS 7,5Kavram kanıtıEPSS %10osticket · osticket sts6 Ara 2004
- CVE-2010-060531İzleyin
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to
YüksekCVSS 7,5Kavram kanıtıEPSS %3osticket · osticket11 Şub 2010
- CVE-2005-215431İzleyin
PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and earlier allows remote attackers to includ
YüksekCVSS 7,5Kavram kanıtıEPSS %2osticket · osticket sts6 Tem 2005
- CVE-2005-143830İzleyin
PHP remote file inclusion vulnerability in main.php in osTicket allows remote attackers to execute arbitrary PHP code via the include_dir pa
YüksekCVSS 7,5İstismar yokEPSS %1osticket · osticket3 May 2005
- CVE-2005-215330İzleyin
SQL injection vulnerability in class.ticket.php in osTicket 1.3.1 beta and earlier allows remote attackers to execute arbitrary SQL commands
YüksekCVSS 7,5İstismar yokEPSS %1osticket · osticket sts6 Tem 2005
- CVE-2005-143730İzleyin
Multiple SQL injection vulnerabilities in osTicket allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to admi
YüksekCVSS 7,5İstismar yokEPSS %1osticket · osticket3 May 2005
- CVE-2004-061425İzleyin
osTicket trusts a hidden form field in the submit form to limit the upload size of a document, which could allow remote attackers to upload
OrtaCVSS 6,4İstismar yokEPSS %1osticket · osticket sts6 Ara 2004
- CVE-2017-1536224İzleyin
osTicket 1.10.1 allows arbitrary client-side JavaScript code execution on victims who click a crafted support/scp/tickets.php?status= link,
OrtaCVSS 6,1İstismar yokEPSS %1osticket · osticket15 Eki 2017
- CVE-2025-4538721İzleyin
osTicket prior to v1.17.6 and v1.18.2 are vulnerable to Broken Access Control Vulnerability in /scp/ajax.php.
OrtaCVSS 5,4İstismar yokEPSS %0osticket · osticket2 Haz 2025
- CVE-2006-673317İzleyin
Cross-site scripting (XSS) vulnerability in support/view.php in Support Cards 1 (osTicket) allows remote attackers to inject arbitrary web s
OrtaCVSS 4,3Kavram kanıtıEPSS %2osticket · osticket sts26 Ara 2006
- CVE-2010-060614İzleyin
Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitra
DüşükCVSS 3,5İstismar yokEPSS %1osticket · osticket11 Şub 2010