Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.803934
Categoría:Web application abuses
Título:OTRS Subaction XSS Vulnerability
Resumen:OTRS (Open Ticket Request System) is prone to a cross-site scripting (XSS) vulnerability.
Descripción:Summary:
OTRS (Open Ticket Request System) is prone to a cross-site scripting (XSS) vulnerability.

Vulnerability Insight:
An error exists in index.pl script which fails to validate user-supplied
input to Subaction parameter properly.

Vulnerability Impact:
Successful exploitation will allow remote attackers to steal the victim's
cookie-based authentication credentials.

Affected Software/OS:
OTRS (Open Ticket Request System) version 2.0.1 to 2.0.4

Solution:
Upgrade to OTRS (Open Ticket Request System) version 2.0.5 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2007-2524
BugTraq ID: 23862
http://www.securityfocus.com/bid/23862
Bugtraq: 20070507 OTRS <= 2.0.x XSS/XSRF (Google Search)
http://www.securityfocus.com/archive/1/467870/100/0/threaded
Bugtraq: 20070611 Re: [SECURITY] [DSA 1299-1] New ipsec-tools packages fix denial ofservice (Google Search)
http://www.securityfocus.com/archive/1/471192/100/0/threaded
Debian Security Information: DSA-1298 (Google Search)
http://www.debian.org/security/2007/dsa-1298
http://www.virtuax.be/?page=library&id=35&type=Exploits
http://osvdb.org/35821
http://osvdb.org/35822
http://secunia.com/advisories/25205
http://secunia.com/advisories/25419
http://secunia.com/advisories/25787
http://securityreason.com/securityalert/2668
SuSE Security Announcement: SUSE-SR:2007:013 (Google Search)
http://www.novell.com/linux/security/advisories/2007_13_sr.html
http://www.vupen.com/english/advisories/2007/1698
XForce ISS Database: otrs-indexpl-xss(34164)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34164
CopyrightCopyright (C) 2013 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.