Vulnerability Name: | CVE-2005-3893 (CCN-23352) | ||||||||||||
Assigned: | 2005-11-22 | ||||||||||||
Published: | 2005-11-22 | ||||||||||||
Updated: | 2017-07-20 | ||||||||||||
Summary: | Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action. | ||||||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Nov 22 2005 - 15:31:42 CST OTRS 1.x/2.x Multiple Security Issues Source: MITRE Type: CNA CVE-2005-3893 Source: FULLDISC Type: UNKNOWN 20051122 OTRS 1.x/2.x Multiple Security Issues Source: BUGTRAQ Type: UNKNOWN 20051122 OTRS 1.x/2.x Multiple Security Issues Source: MISC Type: Exploit, Patch, Vendor Advisory http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt Source: CCN Type: OTRS Web site OTRS::Email Management::Trouble Ticket System::Welcome! Source: CONFIRM Type: Patch, Vendor Advisory http://otrs.org/advisory/OSA-2005-01-en/ Source: CCN Type: SA17685 OTRS SQL Injection and Cross-Site Scripting Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 17685 Source: SECUNIA Type: UNKNOWN 18101 Source: SECUNIA Type: UNKNOWN 18887 Source: CCN Type: SECTRACK ID: 1015262 OTRS Input Validation Bugs Permit SQL Injection and Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1015262 Source: DEBIAN Type: UNKNOWN DSA-973 Source: DEBIAN Type: DSA-973 otrs -- several vulnerabilities Source: SUSE Type: UNKNOWN SUSE-SR:2005:030 Source: OSVDB Type: UNKNOWN 21064 Source: OSVDB Type: UNKNOWN 21065 Source: CCN Type: OSVDB ID: 21064 OTRS (Open Ticket Request System) Login Function User Parameter SQL Injection Source: CCN Type: OSVDB ID: 21065 OTRS (Open Ticket Request System) AgentTicketPlain Action Multiple Parameter SQL Injection Source: CCN Type: BID-15537 OTRS Multiple Input Validation Vulnerabilities Source: BID Type: Exploit, Patch 15537 Source: VUPEN Type: UNKNOWN ADV-2005-2535 Source: XF Type: UNKNOWN otrs-login-sql-injection(23352) Source: XF Type: UNKNOWN otrs-login-sql-injection(23352) Source: XF Type: UNKNOWN otrs-agentticketplain-sql-injection(23354) Source: SUSE Type: SUSE-SR:2005:030 SUSE Security Summary Report | ||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |