Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2021-45811 PoC — Enhancesoft osTicket SQL注入漏洞

Source
Associated Vulnerability
Title:Enhancesoft osTicket SQL注入漏洞 (CVE-2021-45811)
Description:Enhancesoft osTicket是美国Enhancesoft公司的一套开源的票务系统。 Enhancesoft osTicket v1.15.6版本存在安全漏洞,该漏洞源于tickets.php页面的中的Search功能中存在 SQL 注入漏洞,允许经过身份验证的攻击者通过keywords和topic_id 参数执行任意 SQL 命令。
Description
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket 1.15.x allows authenticated attackers to execute arbitrary SQL commands via the "keywords" and "topic_id" URL parameters combination.
File Snapshot

id: CVE-2021-45811 info: name: osTicket 1.15.x - SQL Injection author: ritikchaddha severity: ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.