LWN.net Logo

otrs: multiple vulnerabilities

Package(s):otrs CVE #(s):CVE-2005-3893 CVE-2005-3894 CVE-2005-3895
Created:December 16, 2005 Updated:February 15, 2006
Description: Several vulnerabilities were discovered in the CMS system OTRS. Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, multiple cross-site scripting vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, and Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment.
Alerts:
Debian DSA-973-1 2006-02-15
SuSE SUSE-SR:2005:030 2005-12-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds