CVE-2004-0613
osTicket - Unauthenticated Arbitrary File Upload and Remote Code Execution via Ticket Attachment
Title source: manualExploitation Summary
EIP tracks 1 public exploit for CVE-2004-0613. PoCs published by Guy Pearce.
AI-analyzed exploit summary This exploit leverages a predictable file naming vulnerability in osTicket to achieve remote command execution. The provided PHP code is a simple command execution interface, demonstrating the impact of the vulnerability.
Description
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.
Exploits (1)
This exploit leverages a predictable file naming vulnerability in osTicket to achieve remote command execution. The provided PHP code is a simple command execution interface, demonstrating the impact of the vulnerability.