Support Incident Tracker

Vendor:

First CVE: Oct 23, 2007 · Active for 18 years

22
Total CVEs
More Total CVEs than 94% of tracked products
5.5
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.1
Avg CVSS
Higher Avg CVSS than 21% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Support Incident Tracker over time

Volume of CVEsAvg CVSS Base Score
First CVE
Oct 23, 2007
18 years ago
Most Recent CVE
Jan 2, 2020
2,398 days ago

CVE Severity & Scoring

Support Incident Tracker22 CVEs
All CVEs352,785 CVEs
MediumHigh
Attack Vector
Local0 (0.0%)
Network4 (18.2%)
Unknown18 (81.8%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (18.2%)
High0 (0.0%)
Unknown18 (81.8%)
User Interaction
None0 (0.0%)
Unknown18 (81.8%)
Required4 (18.2%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None4 (18.2%)
Unknown18 (81.8%)

Top CVEs

Signals from CVEs in this product scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Unrestricted file upload vulnerability in ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to execute arbitrary PHP code by uploadi
Jan 29, 20126.047NOYES
ftp_upload_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation
Jan 29, 20124.040NOYES
Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to inject arbitrary PHP code into an executabl
Jan 29, 20127.532NOYES
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to execute arbitrary SQL commands via the (1) start parameter to po
Jan 29, 20127.531NOYES
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to re
Jan 29, 20127.531NOYES
Multiple cross-site request forgery (CSRF) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to hijack the authentication of administrators
Jan 29, 20126.830NOYES
translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive information via a direct request using the save action, which rev
Jan 29, 20125.026NOYES
Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.
Oct 23, 200710.025NONO
Multiple cross-site scripting (XSS) vulnerabilities in Support Incident Tracker (aka SiT!) before 3.65 allow remote attackers to inject arbitrary web script or HTML via the (1) mod
Jan 29, 20124.324NOYES
SQL injection vulnerability in incident_attachments.php in Support Incident Tracker (aka SiT!) 3.65 allows remote attackers to execute arbitrary SQL commands via an uploaded file w
Jan 29, 20127.522NONO

Exploit Exposure

Signals from CVEs in this product scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
9.1% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
8 CVEs
36.4% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (22 CVEs).

Media Mentions

Signals from CVEs in this product scope (22 CVEs).

Top CNAs Publishing CVEs For Support Incident Tracker

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.8.0014.31.0%00
8.8.0014.31.0%00
7.8.0014.31.0%00
4.8.0014.31.0%00
3.6746.10.7%00
3.65115.64.8%04
3.6435.62.1%02
3.6376.01.7%06
3.6276.11.6%06
3.6176.11.6%06
3.6076.11.6%06
3.676.11.6%06
3.5176.11.6%06
3.5086.21.6%06
3.4586.21.6%06
3.4156.61.3%04
3.4056.61.3%04
3.3656.61.3%04
3.3556.61.3%04
3.3356.61.3%04