Vulnerabilities > CVE-2005-3893 - Unspecified vulnerability in Otrs
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Exploit-Db
description OTRS 2.0 Login Function User Parameter SQL Injection. CVE-2005-3893. Webapps exploit for cgi platform id EDB-ID:26550 last seen 2016-02-03 modified 2005-11-22 published 2005-11-22 reporter Moritz Naumann source https://www.exploit-db.com/download/26550/ title OTRS 2.0 - Login Function User Parameter SQL Injection description OTRS 2.0 AgentTicketPlain Action Multiple Parameter SQL Injection. CVE-2005-3893. Webapps exploit for cgi platform id EDB-ID:26551 last seen 2016-02-03 modified 2005-11-22 published 2005-11-22 reporter Moritz Naumann source https://www.exploit-db.com/download/26551/ title OTRS 2.0 - AgentTicketPlain Action Multiple Parameter SQL Injection
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-973.NASL |
description | Several vulnerabilities have been discovered in otrs, the Open Ticket Request System, that can be exploited remotely. The Common Vulnerabilities and Exposures Project identifies the following problems : - CVE-2005-3893 Multiple SQL injection vulnerabilities allow remote attackers to execute arbitrary SQL commands and bypass authentication. - CVE-2005-3894 Multiple cross-site scripting vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML. - CVE-2005-3895 Internally attached text/html mails are rendered as HTML when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22839 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22839 |
title | Debian DSA-973-1 : otrs - several vulnerabilities |
code |
|
References
- http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt
- http://otrs.org/advisory/OSA-2005-01-en/
- http://www.securityfocus.com/bid/15537/
- http://secunia.com/advisories/17685/
- http://www.osvdb.org/21064
- http://www.osvdb.org/21065
- http://securitytracker.com/id?1015262
- http://www.novell.com/linux/security/advisories/2005_30_sr.html
- http://secunia.com/advisories/18101
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html
- http://www.debian.org/security/2006/dsa-973
- http://secunia.com/advisories/18887
- http://www.vupen.com/english/advisories/2005/2535
- http://marc.info/?l=bugtraq&m=113272360804853&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23354
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23352