Vulnerability index

Browse CVEs

39 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Osticket MEDIUM 6.1
CVE-2018-7192

Cross-site scripting (XSS) vulnerability in /ajax.php/form/help-topic in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitra…

Fix: after 1.10.1
Fix from $1,600 2018-03-27
Osticket MEDIUM 6.1
CVE-2018-7193

Cross-site scripting (XSS) vulnerability in /scp/directory.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web …

Fix: after 1.10.1
Fix from $1,600 2018-03-27
Osticket MEDIUM 6.1
CVE-2018-7196

Cross-site scripting (XSS) vulnerability in /scp/index.php in Enhancesoft osTicket before 1.10.2 allows remote attackers to inject arbitrary web scri…

Fix: after 1.10.1
Fix from $1,600 2018-03-27
Osticket MEDIUM 5.0
CVE-2010-4634

Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.…

No fix yet
Fix from $1,600 2010-12-30
Osticket HIGH 7.5
CVE-2010-0605

SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute a…

Fix: after 1.6
Fix from $1,950 2010-02-11
Osticket HIGH 7.5
CVE-2009-2361EPSS 5%

SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the s…

Fix: after 1.6
Fix from $1,950 2009-07-08
Osticket HIGH 7.5
CVE-2006-5407

PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_d…

Mitigation only
Fix from $1,950 2006-10-19
Osticket HIGH 7.5
CVE-2005-1439

Directory traversal vulnerability in attachments.php in osTicket allows remote attackers to read arbitrary files via .. sequences in the file paramet…

Mitigation only
Fix from $1,950 2005-05-03
Osticket MEDIUM 6.8
CVE-2005-1436

Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter…

No fix yet
Fix from $1,600 2005-05-03