7.5
CVSSv2

CVE-2010-0605

Published: 11/02/2010 Updated: 12/02/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 755
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

SQL injection vulnerability in scp/ajax.php in osTicket prior to 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

osticket osticket 1.2.7

osticket osticket 1.6

osticket osticket 1.3.0

osticket osticket 1

osticket osticket

Exploits

Advisory Name: SQL injection in osTicket Vulnerability Class: SQL injection Release Date: 2010-02-09 Affected Applications: Confirmed in osTicket 16 RC5 Other versions may also be affected Affected Platforms: Multiple Local / Remote: Remote Severity: High – CVSS: 9 (AV:N/AC:L/Au:S/C:C/I:C/A:C) Researcher: Nahuel Grisolía Vendor Status ...