CVE-2005-3639 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 2.8% (pctl 86)
Patch early
A public exploit exists.
Description
PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to access or include arbitrary files via the file parameter, possibly due to a directory traversal vulnerability.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 2.75% — more likely to be exploited than 86% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-11-16 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| ubertec | help center live |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Help Center Live 1.0/1.2/2.0 - 'module.php' Local File Inclusion | 2005-11-14 |
References
→ the Explorer · watch your stack · NVD