7.5
CVSSv2

CVE-2009-2361

Published: 08/07/2009 Updated: 10/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in include/class.staff.php in osTicket prior to 1.6 RC5 allows remote malicious users to execute arbitrary SQL commands via the staff username parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

osticket osticket 1.6

osticket osticket

Exploits

nGenuity Information Services - Security Advisory Advisory ID: NGENUITY-2009-007 osTicket Admin Login Blind SQL Injection Application: osTicket v16 RC4 Vendor: osTicket Vendor website: wwwosticketcom Author: Adam Baldwin (adam_baldwin@ngenuity-iscom) I BACKGROUND "osTicket is a widely-used open source suppo ...