CVE-2010-4634: Path Traversal
Published Dec 30, 2010
·Updated
DISPUTED Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a different vector than CVE-2005-1439. NOTE: this issue has been disputed by a reliable third party.
Affected Software
2 affected components
osTicket osTicket=1.6
Enhancesoft osTicket=1.6
Event History
Dec 30, 2010
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Disputed
09:00 PM
Data Sourced
via NVD·09:00 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2010-4634?
The severity of CVE-2010-4634 is considered moderate due to the potential for unauthorized file access.
2
How do I fix CVE-2010-4634?
To fix CVE-2010-4634, ensure that the osTicket application is upgraded to a version that addresses this vulnerability.
3
What type of vulnerability is CVE-2010-4634?
CVE-2010-4634 is a directory traversal vulnerability.
4
Can CVE-2010-4634 be exploited remotely?
Yes, CVE-2010-4634 can be exploited remotely by attackers to read arbitrary files.
5
Which version of osTicket is affected by CVE-2010-4634?
osTicket version 1.6 is affected by CVE-2010-4634.