CVE-2009-2361: SQL Injection
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-2361?
CVE-2009-2361 is classified as a high severity SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands.
How do I fix CVE-2009-2361?
To fix CVE-2009-2361, upgrade to osTicket version 1.6 RC5 or later to eliminate the vulnerability.
What systems are affected by CVE-2009-2361?
CVE-2009-2361 affects osTicket versions 1.6 RC1, 1.6 RC2, 1.6 RC3, and all prior 1.6 RC4 versions.
What is an SQL injection in the context of CVE-2009-2361?
SQL injection in the context of CVE-2009-2361 refers to the ability of an attacker to manipulate SQL queries through the staff username parameter.
Can CVE-2009-2361 lead to data breaches?
Yes, CVE-2009-2361 can lead to data breaches as it allows attackers to execute arbitrary SQL commands that may reveal sensitive data.