CVE-2011-3833

Support Incident Tracker Remote Command Execution

Title source: metasploit

Description

Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in an unspecified directory.

Exploits (2)

exploitdb WORKING POC VERIFIED
by Metasploit · rubywebappsphp
https://www.exploit-db.com/exploits/18108
metasploit WORKING POC EXCELLENT
by Secunia Research, juan vazquez · rubypocphp
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/sit_file_upload.rb

Scores

EPSS 0.1915
EPSS Percentile 95.4%

Details

Status published
Products (1)
sitracker/support_incident_tracker 3.65
Published Jan 29, 2012
Tracked Since Feb 18, 2026