Описание
SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbitrary SQL commands via an uploaded file with a crafted file name.
Ссылки
- Vendor Advisory
- Vendor Advisory
- US Government Resource
- Exploit
- Vendor Advisory
- Vendor Advisory
- US Government Resource
- Exploit
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:sitracker:support_incident_tracker:3.65:*:*:*:*:*:*:*
EPSS
Процентиль: 75%
0.00889
Низкий
7.5 High
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
больше 3 лет назад
SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbitrary SQL commands via an uploaded file with a crafted file name.
EPSS
Процентиль: 75%
0.00889
Низкий
7.5 High
CVSS2
Дефекты
CWE-89