CVE-2017-15580
osTicket 1.10.1 - Arbitrary File Upload
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
4Exploited in Wild
-Decision
Descriptions
osTicket 1.10.1 provides a functionality to upload 'html' files with associated formats. However, it does not properly validate the uploaded file's contents and thus accepts any type of file, such as with a tickets.php request that is modified with a .html extension changed to a .exe extension. An attacker can leverage this vulnerability to upload arbitrary files on the web application having malicious content.
osTicket 1.10.1 proporciona una funcionalidad para subir archivos html con formatos asociados. Sin embargo, no valida correctamente los contenidos de los archivos subidos y por lo tanto acepta cualquier tipo de archivo, como en el caso de una petición tickets.php que se modifica con una extensión .html cambiada a una extensión .exe. Un atacante podrÃa utilizar esta vulnerabilidad para subir archivos arbitrarios que contengan contenidos maliciosos a la aplicación web.
osTicket version 1.10.1 suffers from a remote shell upload vulnerability.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-10-17 CVE Reserved
- 2017-10-23 CVE Published
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://0day.today/exploits/28864 | Third Party Advisory | |
http://nakedsecurity.com/cve/CVE-2017-15580 | Third Party Advisory | |
https://www.cyber-security.ro/blog/2017/10/25/osticket-1-10-1-shell-upload | Broken Link |
URL | Date | SRC |
---|
URL | Date | SRC |
---|