LWN.net Logo

otrs2: SQL injection vulnerability

Package(s):otrs2 CVE #(s):CVE-2010-0438
Created:February 11, 2010 Updated:August 2, 2010
Description: From the Debian alert:

It was discovered that otrs2, the Open Ticket Request System, does not properly sanitise input data that is used on SQL queries, which might be used to inject arbitrary SQL to, for example, escalate privileges on a system that uses otrs2.

Alerts:
SUSE SUSE-SR:2010:014 2010-08-02
openSUSE openSUSE-SU-2010:0366-1 2010-07-13
Debian DSA-1993-1 2010-02-10

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds