CVE-2011-5071

Support Incident Tracker < 3.64 - SQL Injection via Multiple Parameters

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2011-5071. PoCs published by Yuri Goltsev.

AI-analyzed exploit summary The provided text describes a SQL injection vulnerability in Support Incident Tracker 3.63p1, where the 'selected[]' parameter in the 'tasks.php' endpoint is not properly sanitized. The example URL demonstrates how an attacker could inject malicious SQL queries.

Description

Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[] parameter to billable_incidents.php, or (4) search_string parameter to search.php. NOTE: some of these details are obtained from third party information.

Exploits (4)

exploitdb WRITEUP VERIFIED
by Yuri Goltsev · textwebappsphp
https://www.exploit-db.com/exploits/35988

The provided text describes a SQL injection vulnerability in Support Incident Tracker 3.63p1, where the 'selected[]' parameter in the 'tasks.php' endpoint is not properly sanitized. The example URL demonstrates how an attacker could inject malicious SQL queries.

Classification
Writeup 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Support Incident Tracker 3.63p1
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Yuri Goltsev · textwebappsphp
https://www.exploit-db.com/exploits/35987

This exploit demonstrates a SQL injection vulnerability in Support Incident Tracker by injecting a UNION-based query to retrieve the database version. The vulnerability arises from insufficient input sanitization in the 'search_string' parameter.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Support Incident Tracker 3.63p1
No auth needed
Prerequisites: Access to the vulnerable search.php endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Yuri Goltsev · textwebappsphp
https://www.exploit-db.com/exploits/35985

This exploit demonstrates a SQL injection vulnerability in Support Incident Tracker by injecting a single quote into the 'exc[0]' parameter in the report_marketing.php page. The lack of input sanitization allows attackers to manipulate SQL queries, potentially leading to unauthorized data access or modification.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Support Incident Tracker 3.63p1
No auth needed
Prerequisites: Access to the vulnerable web application
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Yuri Goltsev · textwebappsphp
https://www.exploit-db.com/exploits/35986

This exploit demonstrates a SQL injection vulnerability in Support Incident Tracker 3.63p1. The PoC uses a UNION-based SQLi to extract user and database information via the 'sites[]' parameter.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Support Incident Tracker 3.63p1
No auth needed
Prerequisites: Access to the vulnerable endpoint
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (5)

Core 5
Core References
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45437
Mailing List mailing-list x_refsource_bugtraq
http://seclists.org/bugtraq/2011/Jul/174
Various Sources x_refsource_misc
http://en.securitylab.ru/lab/PT-2011-25
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/45277
Third Party Advisory x_refsource_confirm
http://sitracker.org/wiki/ReleaseNotes364

Scores

EPSS 0.0111
EPSS Percentile 61.8%

Details

CWE
CWE-89
Status published
Products (22)
sitracker/support_incident_tracker 3.6
sitracker/support_incident_tracker 3.21
sitracker/support_incident_tracker 3.22
sitracker/support_incident_tracker 3.22pl1
sitracker/support_incident_tracker 3.23
sitracker/support_incident_tracker 3.24 (2 CPE variants)
sitracker/support_incident_tracker 3.30 (2 CPE variants)
sitracker/support_incident_tracker 3.31
sitracker/support_incident_tracker 3.32
sitracker/support_incident_tracker 3.33
... and 12 more
Published Jan 29, 2012
Tracked Since Feb 18, 2026