Unrated severityNVD Advisory· Published Jul 8, 2009· Updated Apr 23, 2026
CVE-2009-2361
CVE-2009-2361
Description
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.
Affected products
4Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- www.ngenuity.org/wordpress/2009/06/26/osticket-admin-login-blind-sql-injection/nvdExploit
- osticket.com/forums/project.phpnvdVendor Advisory
- secunia.com/advisories/35629nvdVendor Advisory
- www.vupen.com/english/advisories/2009/1726nvdVendor Advisory
- www.exploit-db.com/exploits/9032nvd
- www.osvdb.org/55472nvd
- www.securityfocus.com/archive/1/504615/100/0/threadednvd
- www.securityfocus.com/bid/35516nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/51417nvd
News mentions
0No linked articles in our index yet.