Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2020-15308
Disclosure Date: June 26, 2020 (last updated February 21, 2025)
Support Incident Tracker (aka SiT! or SiTracker) 3.67 p2 allows post-authentication SQL injection via the site_edit.php typeid or site parameter, the search_incidents_advanced.php search_title parameter, or the report_qbe.php criteriafield parameter.
0
Attacker Value
Unknown
CVE-2019-20220
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
In Support Incident Tracker (SiT!) 3.67, the search_id parameter in the search_incidents_advanced.php page is affected by XSS.
0
Attacker Value
Unknown
CVE-2019-20221
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
In Support Incident Tracker (SiT!) 3.67, Load Plugins input in the config.php page is affected by XSS. The XSS payload is, for example, executed on the about.php page.
0
Attacker Value
Unknown
CVE-2019-20223
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
In Support Incident Tracker (SiT!) 3.67, the id parameter is affected by XSS on all endpoints that use this parameter, a related issue to CVE-2012-2235.
0
Attacker Value
Unknown
CVE-2019-20222
Disclosure Date: January 02, 2020 (last updated February 21, 2025)
In Support Incident Tracker (SiT!) 3.67, the Short Application Name and Application Name inputs in the config.php page are affected by XSS.
0