CVE-2010-0605
SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with "Staff" permissions, to execute arbitrary SQL commands via the input parameter.
- Affected products
- Osticket
- Enhancesoft Osticket
- ≤ 1.6, 1.2.7, 1.3.0
- Osticket
- = 1
- Fix
- Available
- CVSS 2.0
- 7.5 HIGH
- EPSS
- 3.0% (87th percentile)
- Weakness
- CWE-89
- NVD status
- Modified
- Published
- 2010-02-11
CVE-2010-0605 at NVD
1 known exploit for CVE-2010-0605
Proof-of-concept code and exploit modules indexed by Sploitus