CVE-2009-2361
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.
- Affected products
- Osticket
- Enhancesoft Osticket
- ≤ 1.6
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 5.2% (92th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2009-07-08
CVE-2009-2361 at NVD
1 known exploit for CVE-2009-2361
Proof-of-concept code and exploit modules indexed by Sploitus