Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-15580

osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.384
EPSS Ranking 97.1%
CVSS Severity
CVSS v3 Score 9.8
CVSS v2 Score 7.5
References
Products affected by CVE-2017-15580


Contact Us

Shodan ® - All rights reserved