CVE-2005-3893

Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.
References
Link Resource
http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html
http://marc.info/?l=bugtraq&m=113272360804853&w=2
http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt Exploit Patch Vendor Advisory
http://otrs.org/advisory/OSA-2005-01-en/ Patch Vendor Advisory
http://secunia.com/advisories/17685/ Patch Vendor Advisory
http://secunia.com/advisories/18101
http://secunia.com/advisories/18887
http://securitytracker.com/id?1015262
http://www.debian.org/security/2006/dsa-973
http://www.novell.com/linux/security/advisories/2005_30_sr.html
http://www.osvdb.org/21064
http://www.osvdb.org/21065
http://www.securityfocus.com/bid/15537/ Exploit Patch
http://www.vupen.com/english/advisories/2005/2535
https://exchange.xforce.ibmcloud.com/vulnerabilities/23352
https://exchange.xforce.ibmcloud.com/vulnerabilities/23354
http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html
http://marc.info/?l=bugtraq&m=113272360804853&w=2
http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt Exploit Patch Vendor Advisory
http://otrs.org/advisory/OSA-2005-01-en/ Patch Vendor Advisory
http://secunia.com/advisories/17685/ Patch Vendor Advisory
http://secunia.com/advisories/18101
http://secunia.com/advisories/18887
http://securitytracker.com/id?1015262
http://www.debian.org/security/2006/dsa-973
http://www.novell.com/linux/security/advisories/2005_30_sr.html
http://www.osvdb.org/21064
http://www.osvdb.org/21065
http://www.securityfocus.com/bid/15537/ Exploit Patch
http://www.vupen.com/english/advisories/2005/2535
https://exchange.xforce.ibmcloud.com/vulnerabilities/23352
https://exchange.xforce.ibmcloud.com/vulnerabilities/23354
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.0.3:*:*:*:*:*:*:*

History

21 Nov 2024, 00:02

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html -
References () http://marc.info/?l=bugtraq&m=113272360804853&w=2 - () http://marc.info/?l=bugtraq&m=113272360804853&w=2 -
References () http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt - Exploit, Patch, Vendor Advisory () http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt - Exploit, Patch, Vendor Advisory
References () http://otrs.org/advisory/OSA-2005-01-en/ - Patch, Vendor Advisory () http://otrs.org/advisory/OSA-2005-01-en/ - Patch, Vendor Advisory
References () http://secunia.com/advisories/17685/ - Patch, Vendor Advisory () http://secunia.com/advisories/17685/ - Patch, Vendor Advisory
References () http://secunia.com/advisories/18101 - () http://secunia.com/advisories/18101 -
References () http://secunia.com/advisories/18887 - () http://secunia.com/advisories/18887 -
References () http://securitytracker.com/id?1015262 - () http://securitytracker.com/id?1015262 -
References () http://www.debian.org/security/2006/dsa-973 - () http://www.debian.org/security/2006/dsa-973 -
References () http://www.novell.com/linux/security/advisories/2005_30_sr.html - () http://www.novell.com/linux/security/advisories/2005_30_sr.html -
References () http://www.osvdb.org/21064 - () http://www.osvdb.org/21064 -
References () http://www.osvdb.org/21065 - () http://www.osvdb.org/21065 -
References () http://www.securityfocus.com/bid/15537/ - Exploit, Patch () http://www.securityfocus.com/bid/15537/ - Exploit, Patch
References () http://www.vupen.com/english/advisories/2005/2535 - () http://www.vupen.com/english/advisories/2005/2535 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/23352 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/23352 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/23354 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/23354 -

Information

Published : 2005-11-29 21:03

Updated : 2024-11-21 00:02


NVD link : CVE-2005-3893

Mitre link : CVE-2005-3893

CVE.ORG link : CVE-2005-3893


JSON object : View

Products Affected

otrs

  • otrs