Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2007-2524
Description:Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this identifier for an ipsec-tools issue, but the proper identifier for the ipsec-tools issue is CVE-2007-1841.
Test IDs: 1.3.6.1.4.1.25623.1.0.58348   1.3.6.1.4.1.25623.1.0.803934  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2007-2524
BugTraq ID: 23862
http://www.securityfocus.com/bid/23862
Bugtraq: 20070507 OTRS <= 2.0.x XSS/XSRF (Google Search)
http://www.securityfocus.com/archive/1/467870/100/0/threaded
Bugtraq: 20070611 Re: [SECURITY] [DSA 1299-1] New ipsec-tools packages fix denial ofservice (Google Search)
http://www.securityfocus.com/archive/1/471192/100/0/threaded
Debian Security Information: DSA-1298 (Google Search)
http://www.debian.org/security/2007/dsa-1298
http://www.virtuax.be/?page=library&id=35&type=Exploits
http://osvdb.org/35821
http://osvdb.org/35822
http://secunia.com/advisories/25205
http://secunia.com/advisories/25419
http://secunia.com/advisories/25787
http://securityreason.com/securityalert/2668
SuSE Security Announcement: SUSE-SR:2007:013 (Google Search)
http://www.novell.com/linux/security/advisories/2007_13_sr.html
http://www.vupen.com/english/advisories/2007/1698
XForce ISS Database: otrs-indexpl-xss(34164)
https://exchange.xforce.ibmcloud.com/vulnerabilities/34164




© 1998-2025 E-Soft Inc. All rights reserved.