7.5
CVSSv2

CVE-2005-2154

Published: 06/07/2005 Updated: 05/09/2008
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

PHP local file inclusion vulnerability in (1) view.php and (2) open.php in osTicket 1.3.1 beta and previous versions allows remote malicious users to include and possibly execute arbitrary local files via the inc parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

osticket osticket sts 1.3_beta

osticket osticket sts 1.2.7

osticket osticket sts 1.2

Exploits

source: wwwsecurityfocuscom/bid/14127/info osTicket is affected by multiple input-validation vulnerabilities because the application fails to sufficiently sanitize user-supplied data The following specific issues were identified: - An SQL-injection vulnerability A successful exploit could allow an attacker to compromise the applicatio ...