osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=108786779500957&w=2 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16478 | vdb entry |
http://www.securityfocus.com/bid/10586 | exploit vdb entry patch vendor advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/16477 | vdb entry |