CVE-2017-14396

Published at:
2017-09-12T21:29:00.423

Global infos:

In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

CVE Status: Modified

References:

  • [email protected]
  • af854a3a-2127-422b-91ae-364da2661108
  • Metrics:

    No CVSS data available

    Links:

    Exploit-db
    Github