Vulnerability index

Browse CVEs

7 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Osticket HIGH 7.5
CVE-2023-30082

A denial of service attack might be launched against the server if an unusually lengthy password (more than 10000000 characters) is supplied using th…

No fix yet
Fix from $1,950 2023-06-14
Osticket MEDIUM 5.4
CVE-2020-14012

scp/categories.php in osTicket 1.14.2 allows XSS via a Knowledgebase Category Name or Category Description. The attacker must be an Agent.

No fix yet
Fix from $1,600 2020-06-10
Osticket MEDIUM 6.1
CVE-2019-13397

Unauthenticated Stored XSS in osTicket 1.10.1 allows a remote attacker to gain admin privileges by injecting arbitrary web script or HTML via arbitra…

Mitigation only
Fix from $1,600 2019-07-09
Osticket MEDIUM 5.0
CVE-2010-4634

Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.…

No fix yet
Fix from $1,600 2010-12-30
Osticket HIGH 7.5
CVE-2006-5407

PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_d…

Mitigation only
Fix from $1,950 2006-10-19
Osticket HIGH 7.5
CVE-2005-1439

Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file paramet…

Mitigation only
Fix from $1,950 2005-05-03
Osticket MEDIUM 6.8
CVE-2005-1436

Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter…

No fix yet
Fix from $1,600 2005-05-03