Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · net nu 97 bronnen 2 kritiek 31 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2009-2361

HIGH · 7.5 CVSS Gepubliceerd: CWE-89

Beschrijving

SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.

Vendors

Enhancesoft

Affected products

Osticket

References