Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-14396

Опубликовано: 12 сент. 2017
Источник: debian

Описание

In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
osticketitppackage

Связанные уязвимости

CVSS3: 9.8
nvd
около 9 лет назад

In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

CVSS3: 9.8
github
больше 4 лет назад

In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

Уязвимость CVE-2017-14396