| Vulnerability Name: | CVE-2005-3894 (CCN-23359) | ||||||||||||
| Assigned: | 2005-11-22 | ||||||||||||
| Published: | 2005-11-22 | ||||||||||||
| Updated: | 2017-07-20 | ||||||||||||
| Summary: | Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters. | ||||||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-Other | ||||||||||||
| Vulnerability Consequences: | Gain Access | ||||||||||||
| References: | Source: CCN Type: Full-Disclosure Mailing List, Tue Nov 22 2005 - 15:31:42 CST OTRS 1.x/2.x Multiple Security Issues Source: MITRE Type: CNA CVE-2005-3894 Source: FULLDISC Type: UNKNOWN 20051122 OTRS 1.x/2.x Multiple Security Issues Source: BUGTRAQ Type: UNKNOWN 20051122 OTRS 1.x/2.x Multiple Security Issues Source: MISC Type: Exploit, Patch, Vendor Advisory http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt Source: CCN Type: OTRS Web site OTRS::Email Management::Trouble Ticket System::Welcome! Source: CONFIRM Type: Patch, Vendor Advisory http://otrs.org/advisory/OSA-2005-01-en/ Source: CCN Type: SA17685 OTRS SQL Injection and Cross-Site Scripting Vulnerabilities Source: SECUNIA Type: Patch, Vendor Advisory 17685 Source: SECUNIA Type: UNKNOWN 18101 Source: SECUNIA Type: UNKNOWN 18887 Source: CCN Type: SECTRACK ID: 1015262 OTRS Input Validation Bugs Permit SQL Injection and Cross-Site Scripting Attacks Source: SECTRACK Type: UNKNOWN 1015262 Source: DEBIAN Type: UNKNOWN DSA-973 Source: DEBIAN Type: DSA-973 otrs -- several vulnerabilities Source: SUSE Type: UNKNOWN SUSE-SR:2005:030 Source: OSVDB Type: UNKNOWN 21067 Source: CCN Type: OSVDB ID: 21067 OTRS (Open Ticket Request System) index.pl Multiple Parameter XSS Source: CCN Type: BID-15537 OTRS Multiple Input Validation Vulnerabilities Source: BID Type: Exploit, Patch 15537 Source: VUPEN Type: UNKNOWN ADV-2005-2535 Source: XF Type: UNKNOWN otrs-queue-selection-xss(23356) Source: XF Type: UNKNOWN otrs-index-xss(23359) Source: XF Type: UNKNOWN otrs-index-xss(23359) Source: SUSE Type: SUSE-SR:2005:030 SUSE Security Summary Report | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| Oval Definitions | |||||||||||||
| |||||||||||||
| BACK | |||||||||||||