|
|
| |
| eTicket is "a PHP-based electronic (open source) support ticket system based on osTicket, that can receive tickets via email (pop3/pipe) or a web form. It also offers a ticket manager with many features. An ideal helpdesk solution for any website". The application eTicket version 1.5.6-RC4 is prone to a Cross Site Scripting and path disclosure vulnerabilities. |
| |
Credit:
The information has been provided by Alessandro Tanasi.
The original article can be found at: http://www.lonerunners.net/users/jekil/pub/hack-eticket/hack-eticket.txt
|
| |
Vulnerable Systems:
* eTicket version 1.5.6-RC4
Proof of concept:
http://example.com/index.php/"><script>alert('XSS')</script>
|
|
|