PT-2005-4396 · Osticket+1 · Osticket+1

Published

2005-11-16

·

Updated

2011-03-08

·

CVE-2005-3639

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Help Center Live versions prior to 2.0.3
Description A PHP file inclusion issue in the osTicket module allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal issue.
Recommendations For versions prior to 2.0.3, update to version 2.0.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the osTicket module until the update is applied.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-3639

Affected Products

Help Center Live
Osticket