Vulnerabilities > CVE-2005-3894 - Unspecified vulnerability in Otrs
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 6 |
Exploit-Db
description | OTRS 2.0 index.pl Multiple Parameter XSS. CVE-2005-3894. Webapps exploit for cgi platform |
id | EDB-ID:26552 |
last seen | 2016-02-03 |
modified | 2005-11-22 |
published | 2005-11-22 |
reporter | Moritz Naumann |
source | https://www.exploit-db.com/download/26552/ |
title | OTRS 2.0 index.pl Multiple Parameter XSS |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-973.NASL |
description | Several vulnerabilities have been discovered in otrs, the Open Ticket Request System, that can be exploited remotely. The Common Vulnerabilities and Exposures Project identifies the following problems : - CVE-2005-3893 Multiple SQL injection vulnerabilities allow remote attackers to execute arbitrary SQL commands and bypass authentication. - CVE-2005-3894 Multiple cross-site scripting vulnerabilities allow remote authenticated users to inject arbitrary web script or HTML. - CVE-2005-3895 Internally attached text/html mails are rendered as HTML when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22839 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22839 |
title | Debian DSA-973-1 : otrs - several vulnerabilities |
code |
|
References
- http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt
- http://otrs.org/advisory/OSA-2005-01-en/
- http://www.securityfocus.com/bid/15537/
- http://secunia.com/advisories/17685/
- http://www.osvdb.org/21067
- http://securitytracker.com/id?1015262
- http://www.novell.com/linux/security/advisories/2005_30_sr.html
- http://secunia.com/advisories/18101
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html
- http://www.debian.org/security/2006/dsa-973
- http://secunia.com/advisories/18887
- http://www.vupen.com/english/advisories/2005/2535
- http://marc.info/?l=bugtraq&m=113272360804853&w=2
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23359
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23356