{"id":"CVE-2010-0605","title":"SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with \"Staff\" permissions, to execute arbitrary SQL commands via the input parameter.","summary":"SQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with \"Staff\" permissions, to execute arbitrary SQL commands via the input parameter.","severity":"high","cvss":7.5,"cvssVector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","cwe":["CWE-89"],"vendor":"enhancesoft","product":"osticket","affected":["osticket <= 1.6","osticket = 1.2.7","osticket = 1.3.0","osticket = 1.6","osticket = 1"],"published":"2010-02-11","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2010-0605","references":[{"url":"http://osticket.com/forums/project.php?issueid=176","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.org/1002-exploits/osTicket-1.6-RC5-SQLi.pdf","label":"cve@mitre.org"},{"url":"http://secunia.com/advisories/38515","label":"cve@mitre.org"},{"url":"http://www.exploit-db.com/exploits/11380","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/38166","label":"cve@mitre.org"},{"url":"http://osticket.com/forums/project.php?issueid=176","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.org/1002-exploits/osTicket-1.6-RC5-SQLi.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/38515","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.exploit-db.com/exploits/11380","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/38166","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.03048,"epssPercentile":0.86915,"exploitAvailable":true,"ingestedAt":"2026-07-10T19:05:51.122Z","exploits":{"exploitdb":true,"checkedAt":"2026-09-21T15:23:32.170Z"},"slug":"CVE-2010-0605","body":"## Overview\n\nSQL injection vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users, with \"Staff\" permissions, to execute arbitrary SQL commands via the input parameter.\n\n## Affected\n\n- `osticket <= 1.6`\n- `osticket = 1.2.7`\n- `osticket = 1.3.0`\n- `osticket = 1.6`\n- `osticket = 1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":54,"depthScoreParts":{"impact":41.3,"likelihood":0.6,"exploitation":12,"ransomware":0},"changes":[]}