Unrated severityNVD Advisory· Published Jul 8, 2009· Updated Jun 16, 2026
CVE-2009-2361
CVE-2009-2361
Description
SQL injection vulnerability in include/class.staff.php in osTicket before 1.6 RC5 allows remote attackers to execute arbitrary SQL commands via the staff username parameter.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:a:osticket:osticket:1.6:rc1:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:osticket:osticket:1.6:rc1:*:*:*:*:*:*
- cpe:2.3:a:osticket:osticket:1.6:rc2:*:*:*:*:*:*
- cpe:2.3:a:osticket:osticket:1.6:rc3:*:*:*:*:*:*
- cpe:2.3:a:osticket:osticket:*:rc4:*:*:*:*:*:*range: <=1.6
- (no CPE)range: <1.6 RC5
Patches
Vulnerability mechanics
References
10- www.ngenuity.org/wordpress/2009/06/26/osticket-admin-login-blind-sql-injection/nvdExploit
- osticket.com/forums/project.phpnvdVendor Advisory
- secunia.com/advisories/35629nvdVendor Advisory
- www.vupen.com/english/advisories/2009/1726nvdVendor Advisory
- www.exploit-db.com/exploits/9032nvd
- www.osvdb.org/55472nvd
- www.securityfocus.com/archive/1/504615/100/0/threadednvd
- www.securityfocus.com/bid/35516nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/51417nvd
News mentions
0No linked articles in our index yet.