Eticket is a ticketing and event-management application whose vulnerability footprint concentrates in web-application input-handling and session-management flaws, including cross-site scripting, SQL injection, and cross-site request forgery. The vendor's disclosures frequently acquire public exploit tooling, reflecting the application's web-facing attack surface and the accessibility of these weakness classes to security researchers and tool developers. Defenders tracking this product should prioritize input validation and CSRF-token controls; live severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eticket over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-0267HIGH Multiple SQL injection vulnerabilities in eTicket 1.5.5.2 allow remote authenticated users to execute arbitrary SQL commands via the (1) status, (2) sort, and (3) way parameters to | Jan 15, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-0268MEDIUM Cross-site scripting (XSS) vulnerability in view.php in eTicket 1.5.5.2 allows remote attackers to inject arbitrary web script or HTML via the s parameter. | Jan 15, 2008 | 4.3 | 23 | NO | YES |
CVE-2008-0552MEDIUM Cross-site scripting (XSS) vulnerability in index.php in eTicket 1.5.6-RC4 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | Feb 1, 2008 | 4.3 | 21 | NO | YES |
CVE-2007-2801MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in open.php in eTicket 1.5.5 and 1.5.5.1, when register_globals is enabled, allow remote attackers to inject arbitrary web scrip | Jun 30, 2007 | 4.3 | 21 | NO | YES |
CVE-2008-5165HIGH Multiple SQL injection vulnerabilities in eTicket 1.5.7 allow remote attackers to execute arbitrary SQL commands via the pri parameter to (1) index.php, (2) open.php, (3) open_raw. | Nov 19, 2008 | 7.5 | 19 | NO | NO |
Cross-site request forgery (CSRF) vulnerability in admin.php in eTicket 1.5.5.2 allows remote attackers to change the administrative password and possibly perform other administrat | Jan 15, 2008 | 2.6 | 19 | NO | YES |
CVE-2008-0093MEDIUM Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in eTicket 1.5.5.2, and 1.5.6 RC2 and RC3, allow remote attackers to inject arbitrary web script or HTML via th | Jan 8, 2008 | 4.3 | 16 | NO | NO |
CVE-2007-2800MEDIUM index.php in eTicket 1.5.5.1 and earlier allows remote attackers to obtain sensitive information via the (1) name[], (2) email[], (3) phone[], or (4) subject[] parameters, which re | Jun 28, 2007 | 5.0 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eticket.
Media articles that mention a CVE ID that affects a product developed by Eticket — matched by CVE ID, not by vendor name.