VulnerabilityModified
CVE-2011-3832
Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to execute arbitrary PHP code via the application_name parameter in a save action.
MEDIUM 6.5EPSS 1.39%
Does this matter?
Lower severity and a low EPSS score (1.39%). Track it; it rarely justifies an emergency change on its own.
Description
Eval injection vulnerability in config.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated administrators to execute arbitrary PHP code via the application_name parameter in a save action.
- CVSS 2.0
- 6.5 MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
- EPSS
- 1.39% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94
- Affected
- sitracker/support incident tracker
- Source
- PSIRT-CNA@flexerasoftware.com
References
- http://secunia.com/advisories/45453Vendor Advisory
- http://secunia.com/secunia_research/2011-78/Vendor Advisory
- http://www.osvdb.org/77002
- http://www.securityfocus.com/bid/50632Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71236
- http://secunia.com/advisories/45453Vendor Advisory
- http://secunia.com/secunia_research/2011-78/Vendor Advisory
- http://www.osvdb.org/77002
- http://www.securityfocus.com/bid/50632Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/71236
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.