CVE-2005-3894

Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.
References
Link Resource
http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html
http://marc.info/?l=bugtraq&m=113272360804853&w=2
http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt Exploit Patch Vendor Advisory
http://otrs.org/advisory/OSA-2005-01-en/ Patch Vendor Advisory
http://secunia.com/advisories/17685/ Patch Vendor Advisory
http://secunia.com/advisories/18101
http://secunia.com/advisories/18887
http://securitytracker.com/id?1015262
http://www.debian.org/security/2006/dsa-973
http://www.novell.com/linux/security/advisories/2005_30_sr.html
http://www.osvdb.org/21067
http://www.securityfocus.com/bid/15537/ Exploit Patch
http://www.vupen.com/english/advisories/2005/2535
https://exchange.xforce.ibmcloud.com/vulnerabilities/23356
https://exchange.xforce.ibmcloud.com/vulnerabilities/23359
http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html
http://marc.info/?l=bugtraq&m=113272360804853&w=2
http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt Exploit Patch Vendor Advisory
http://otrs.org/advisory/OSA-2005-01-en/ Patch Vendor Advisory
http://secunia.com/advisories/17685/ Patch Vendor Advisory
http://secunia.com/advisories/18101
http://secunia.com/advisories/18887
http://securitytracker.com/id?1015262
http://www.debian.org/security/2006/dsa-973
http://www.novell.com/linux/security/advisories/2005_30_sr.html
http://www.osvdb.org/21067
http://www.securityfocus.com/bid/15537/ Exploit Patch
http://www.vupen.com/english/advisories/2005/2535
https://exchange.xforce.ibmcloud.com/vulnerabilities/23356
https://exchange.xforce.ibmcloud.com/vulnerabilities/23359
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:otrs:otrs:1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:1.3.2:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.0.0:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.0.1:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.0.2:*:*:*:*:*:*:*
cpe:2.3:a:otrs:otrs:2.0.3:*:*:*:*:*:*:*

History

21 Nov 2024, 00:02

Type Values Removed Values Added
References () http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html - () http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html -
References () http://marc.info/?l=bugtraq&m=113272360804853&w=2 - () http://marc.info/?l=bugtraq&m=113272360804853&w=2 -
References () http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt - Exploit, Patch, Vendor Advisory () http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt - Exploit, Patch, Vendor Advisory
References () http://otrs.org/advisory/OSA-2005-01-en/ - Patch, Vendor Advisory () http://otrs.org/advisory/OSA-2005-01-en/ - Patch, Vendor Advisory
References () http://secunia.com/advisories/17685/ - Patch, Vendor Advisory () http://secunia.com/advisories/17685/ - Patch, Vendor Advisory
References () http://secunia.com/advisories/18101 - () http://secunia.com/advisories/18101 -
References () http://secunia.com/advisories/18887 - () http://secunia.com/advisories/18887 -
References () http://securitytracker.com/id?1015262 - () http://securitytracker.com/id?1015262 -
References () http://www.debian.org/security/2006/dsa-973 - () http://www.debian.org/security/2006/dsa-973 -
References () http://www.novell.com/linux/security/advisories/2005_30_sr.html - () http://www.novell.com/linux/security/advisories/2005_30_sr.html -
References () http://www.osvdb.org/21067 - () http://www.osvdb.org/21067 -
References () http://www.securityfocus.com/bid/15537/ - Exploit, Patch () http://www.securityfocus.com/bid/15537/ - Exploit, Patch
References () http://www.vupen.com/english/advisories/2005/2535 - () http://www.vupen.com/english/advisories/2005/2535 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/23356 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/23356 -
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/23359 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/23359 -

Information

Published : 2005-11-29 21:03

Updated : 2024-11-21 00:02


NVD link : CVE-2005-3894

Mitre link : CVE-2005-3894

CVE.ORG link : CVE-2005-3894


JSON object : View

Products Affected

otrs

  • otrs