CVE-2011-3833
Support Incident Tracker Remote Command Execution
Title source: metasploitDescription
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in an unspecified directory.
Exploits (2)
exploitdb
WORKING POC
VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/18108
metasploit
WORKING POC
EXCELLENT
by Secunia Research, juan vazquez · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/sit_file_upload.rb
References (10)
Scores
EPSS
0.1915
EPSS Percentile
95.4%
Details
Status
published
Products (1)
sitracker/support_incident_tracker
3.65
Published
Jan 29, 2012
Tracked Since
Feb 18, 2026