Vulnerabilities > CVE-2004-0613 - Remote Command Execution vulnerability in Osticket STS 1.2

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
osticket
nessus
exploit available

Summary

osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.

Vulnerable Configurations

Part Description Count
Application
Osticket
1

Exploit-Db

descriptionosTicket STS 1.2 Attachment Remote Command Execution Vulnerability. CVE-2004-0613. Webapps exploit for php platform
idEDB-ID:24225
last seen2016-02-02
modified2004-06-21
published2004-06-21
reporterGuy Pearce
sourcehttps://www.exploit-db.com/download/24225/
titleosTicket STS 1.2 Attachment Remote Command Execution Vulnerability

Nessus

  • NASL familyCGI abuses
    NASL idOSTICKET_ATTACHMENT_CODE_EXECUTION.NASL
    descriptionThe target is running at least one instance of osTicket that enables a remote user to open a new ticket with an attachment containing arbitrary PHP code and then to run that code using the permissions of the web server user.
    last seen2020-06-01
    modified2020-06-02
    plugin id13645
    published2004-07-14
    reporterThis script is Copyright (C) 2004-2018 George A. Theall
    sourcehttps://www.tenable.com/plugins/nessus/13645
    titleosTicket Attachment Handling File Upload Arbitrary Code Execution
  • NASL familyCGI abuses
    NASL idOSTICKET_VIEW_ATTACHMENTS.NASL
    descriptionThe target is running at least one instance of osTicket that enables a remote user to view attachments associated with any existing ticket. These attachments may contain sensitive information.
    last seen2020-06-01
    modified2020-06-02
    plugin id13648
    published2004-07-14
    reporterThis script is Copyright (C) 2004-2018 George A. Theall
    sourcehttps://www.tenable.com/plugins/nessus/13648
    titleosTicket Arbitrary Attachment Disclosure