Количество 3
Количество 3
CVE-2017-15580
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
GHSA-3grx-cccr-q3vw
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
BDU:2018-00154
Уязвимость сценария tickets.php системы поддержки клиентов osTicket, позволяющая нарушителю загружать вредоносные файлы
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2017-15580 osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content. | CVSS3: 9.8 | 36% Средний | больше 8 лет назад | |
GHSA-3grx-cccr-q3vw osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content. | CVSS3: 9.8 | 36% Средний | больше 3 лет назад | |
BDU:2018-00154 Уязвимость сценария tickets.php системы поддержки клиентов osTicket, позволяющая нарушителю загружать вредоносные файлы | CVSS3: 9.8 | 36% Средний | больше 8 лет назад |
Уязвимостей на страницу