CVE-2011-3833 is an unrestricted file upload vulnerability in Support Incident Tracker (SiT!) version 3.65, specifically within the ftp_upload_file.php component. This allows remote authenticated users to execute arbitrary PHP code by uploading a malicious PHP file and then directly accessing it. The vulnerability has a CVSS score of 6.0, indicating a medium severity, with a network-based attack vector, medium access complexity, and potential for partial confidentiality, integrity, and availability impact. While not listed on the KEV catalog, there is a publicly available Metasploit module for remote command execution, suggesting exploitability, though community discussion and media coverage are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.65CPE matchmatch criteria | cpe:2.3:a:sitracker:support_incident_tracker:3.65:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:S/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.