{"id":"CVE-2010-0606","title":"Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/…","summary":"Cross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/…","severity":"low","cvss":3.5,"cvssVector":"AV:N/AC:M/Au:S/C:N/I:P/A:N","cwe":["CWE-79"],"vendor":"enhancesoft","product":"osticket","affected":["osticket <= 1.6","osticket = 1.2.7","osticket = 1.3.0","osticket = 1.6","osticket = 1"],"published":"2010-02-11","updated":"2026-07-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2010-0606","references":[{"url":"http://osticket.com/forums/project.php?issueid=176","label":"cve@mitre.org"},{"url":"http://packetstormsecurity.org/1002-exploits/osTicket-1.6-RC5-ReflectedXSS.pdf","label":"cve@mitre.org"},{"url":"http://secunia.com/advisories/38515","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/38166","label":"cve@mitre.org"},{"url":"http://osticket.com/forums/project.php?issueid=176","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://packetstormsecurity.org/1002-exploits/osTicket-1.6-RC5-ReflectedXSS.pdf","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://secunia.com/advisories/38515","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/38166","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00877,"epssPercentile":0.57007,"ingestedAt":"2026-07-10T19:05:51.134Z","slug":"CVE-2010-0606","body":"## Overview\n\nCross-site scripting (XSS) vulnerability in scp/ajax.php in osTicket before 1.6.0 Stable allows remote authenticated users to inject arbitrary web script or HTML via the f parameter, possibly related to an error message generated by scp/admin.php.\n\n## Affected\n\n- `osticket <= 1.6`\n- `osticket = 1.2.7`\n- `osticket = 1.3.0`\n- `osticket = 1.6`\n- `osticket = 1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":19,"depthScoreParts":{"impact":19.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}