CVE-2005-1436: XSS
Multiple cross-site scripting (XSS) vulnerabilities in osTicket allow remote attackers to inject arbitrary web script or HTML via (1) the t parameter to view.php, (2) the ostickettitle parameter to header.php, (3) the em parameter to adminlogin.php, (4) the e parameter to userlogin.php, (5) the err parameter to opensubmit.php, or (6) the name and subject fields when adding a ticket.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2005-1436?
The severity of CVE-2005-1436 is classified as medium due to its potential to allow XSS attacks.
How do I fix CVE-2005-1436?
To fix CVE-2005-1436, upgrade osTicket to a patched version that addresses the XSS vulnerabilities.
What versions of osTicket are affected by CVE-2005-1436?
CVE-2005-1436 affects osTicket versions 1.2.7 and 1.3.0.
What type of vulnerabilities does CVE-2005-1436 involve?
CVE-2005-1436 involves multiple cross-site scripting (XSS) vulnerabilities.
Can CVE-2005-1436 be exploited remotely?
Yes, CVE-2005-1436 can be exploited remotely by attackers to inject arbitrary web scripts.