CVE-2004-0613: High severity osTicket Osticket Sts vulnerability
Published Jun 30, 2004
·Updated
osTicket allows remote attackers to view sensitive uploaded files and possibly execute arbitrary code via an HTTP request that uploads a PHP file to the ticket attachments directory.
Affected Software
1 affected component
osTicket Osticket Sts=1.2
Remediation
Patch Available
Event History
Jun 30, 2004
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-0613?
CVE-2004-0613 has a moderate severity rating due to its potential for remote code execution.
2
How do I fix CVE-2004-0613?
To fix CVE-2004-0613, ensure that file uploads are restricted to specific file types and that proper validations are in place.
3
What versions of osTicket are affected by CVE-2004-0613?
CVE-2004-0613 affects osTicket version 1.2.
4
What impact does CVE-2004-0613 have on my system?
CVE-2004-0613 can allow attackers to view sensitive files and potentially execute arbitrary code on the server.
5
Are there any known exploit techniques for CVE-2004-0613?
Yes, attackers may exploit CVE-2004-0613 by uploading a malicious PHP file to the attachments directory.