CVE-2009-2361
osticket
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.
- CVSS
- 7.5
- EPSS
- 5.17% 91.6% percentile
- CISA KEV
- Not listed
- Published
- 2009.07.09