20040621 Multiple osTicket exploits!mailing list
http://marc.info/?l=bugtraq&m=108786779500957&w=2 CVE-2004-0613
osTicket STS 1.2 - Attachment Remote Command Execution
Record summary
CVE-2004-0613 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBosTicket STS 1.2 - Attachment Remote Command ExecutionExploitDB exploitby Guy PearceNot analyzed1 file
References
510586vdb entry
http://www.securityfocus.com/bid/10586 osticket-php-file-upload(16477)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16477 osticket-view-attachments(16478)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/16478 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2004-0613