Total vulnerabilities in the database
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.
Software | From | Fixed in |
---|---|---|
osticket / osticket | 1.6-rc1 | 1.6-rc1.x |
osticket / osticket | 1.6-rc3 | 1.6-rc3.x |
osticket / osticket | - | 1.6.x |
osticket / osticket | 1.6-rc2 | 1.6-rc2.x |