Beveiligingsadvies

CVE-2009-2361

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2009-07-08 15:00:00
Laatst bijgewerkt 2024-08-07 05:44:56
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.