6.8
CVSSv2

CVE-2005-1436

Published: 03/05/2005 Updated: 14/07/2013
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote malicious users to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the osticket_title parameter to header.php, (3) the em parameter to admin_login.php, (4) the e parameter to user_login.php, (5) the err parameter to open_submit.php, or (6) the name and subject fields when adding a ticket.

Vulnerable Product Search on Vulmon Subscribe to Product

osticket osticket 1.2.7

osticket osticket 1.3.0