CVE detail
CVE-2006-5407
PHP remote file inclusion vulnerability in open_form.php in osTicket allows remote attackers to execute arbitrary PHP code via a URL in the include_dir parameter.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 13.9 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
3 source links · newest first
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29577exchange.xforce.ibmcloud.com
No excerpt available.
Vendor Advisoryexchange.xforce.ibmcloud.comOct 19, 2006, 1:07 AM - http://www.securityfocus.com/archive/1/448687/100/0/threadedwww.securityfocus.com
No excerpt available.
Exploitwww.securityfocus.comOct 19, 2006, 1:07 AM - http://securityreason.com/securityalert/1745securityreason.com
No excerpt available.
referencesecurityreason.comOct 19, 2006, 1:07 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2025-26241CVSS 6.5 · Medium
A SQL injection vulnerability in the "Search" functionality of "tickets.php" page in osTicket <=1.17.5 allows authenticated attackers to execute arbitrary SQL commands via the "ke…
- CVE-2022-32074CVSS 5.4 · Medium
A stored cross-site scripting (XSS) vulnerability in the component audit/class.audit.php of osTicket-plugins - Storage-FS before commit a7842d494889fd5533d13deb3c6a7789768795ae al…
- CVE-2020-24881CVSS 9.8 · Critical
SSRF exists in osTicket before 1.14.3, where an attacker can add malicious file to server or perform port scanning.
- CVE-2020-24917CVSS 6.1 · Medium
osTicket before 1.14.3 allows XSS via a crafted filename to DraftAjaxAPI::_uploadInlineImage() in include/ajax.draft.php.
- CVE-2020-16193CVSS 5.4 · Medium
osTicket before 1.14.3 allows XSS because include/staff/banrule.inc.php has an unvalidated echo $info['notes'] call.
- CVE-2019-14750CVSS 6.1 · Medium
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. Stored XSS exists in setup/install.php. It was observed that no input sanitization was provided in the…