---
id: CVE-2010-4634
title: >-
  Directory traversal vulnerability in osTicket 1.6 allows remote attackers to
  read arbitrary files via a .
summary: >-
  Directory traversal vulnerability in osTicket 1.6 allows remote attackers to
  read arbitrary files via a .. (dot dot) in the file parameter to module.php, a
  different vector than CVE-2005-1439.  NOTE: this issue has been disputed by a
  rel…
severity: medium
cvss: 5
cvssVector: 'AV:N/AC:L/Au:N/C:P/I:N/A:N'
cwe:
  - CWE-22
vendor: enhancesoft
product: osticket
affected:
  - osticket = 1.6
published: '2010-12-30'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2010-4634'
references:
  - url: 'http://packetstormsecurity.org/1011-exploits/osticket-lfi.txt'
    label: cve@mitre.org
  - url: 'http://www.attrition.org/pipermail/vim/2010-November/002468.html'
    label: cve@mitre.org
  - url: 'http://www.attrition.org/pipermail/vim/2010-November/002469.html'
    label: cve@mitre.org
  - url: 'http://www.exploit-db.com/exploits/15471'
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/44739'
    label: cve@mitre.org
  - url: 'http://packetstormsecurity.org/1011-exploits/osticket-lfi.txt'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.attrition.org/pipermail/vim/2010-November/002468.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.attrition.org/pipermail/vim/2010-November/002469.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.exploit-db.com/exploits/15471'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://www.securityfocus.com/bid/44739'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.02496
epssPercentile: 0.8386
ingestedAt: '2026-07-10T19:05:51.139Z'
---

## Overview

Directory traversal vulnerability in osTicket 1.6 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to module.php, a different vector than CVE-2005-1439.  NOTE: this issue has been disputed by a reliable third party

## Affected

- `osticket = 1.6`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
