CVE-2005-4617

cSupport < 1.0 - SQL Injection via tickets.php pg Parameter

Title source: llm
STIX 2.1

Description

SQL injection vulnerability in tickets.php in cSupport 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the pg parameter.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/21316
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24358

Scores

EPSS 0.0132
EPSS Percentile 67.9%

Details

CWE
CWE-89
Status published
Products (1)
forperfect/csupport < 1.0
Published Dec 31, 2005
Tracked Since Feb 18, 2026