Scorz-Root

osTicket 1.2/1.3 - 'view.php?inc' Arbitrary Local File

Dec 16th, 2017
1,491
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.79 KB | None | 0 0
  1. source: http://www.securityfocus.com/bid/14127/info
  2.  
  3. osTicket is affected by multiple input-validation vulnerabilities because the application fails to sufficiently sanitize user-supplied data.
  4.  
  5. The following specific issues were identified:
  6.  
  7. - An SQL-injection vulnerability. A successful exploit could allow an attacker to compromise the application, access or modify data, or exploit vulnerabilities in the underlying database implementation.
  8.  
  9. - A local file-include vulnerability. An attacker may leverage this issue to execute arbitrary server-side script code that resides on an affected computer with the privileges of the webserver process. This may facilitate unauthorized access.
  10.  
  11. osTicket 1.3.1 beta and prior versions are affected.
  12.  
  13. http://www.example.com/osticket/view.php?inc=x
Advertisement
Add Comment
Please, Sign In to add comment