PT-2005-5581 · Otrs · Open Ticket Request System

Moritz Naumann

·

Published

1970-01-01

·

Updated

2017-07-20

·

CVE-2005-3894

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Open Ticket Request System (OTRS) versions 1.0.0 through 1.3.2 Open Ticket Request System (OTRS) versions 2.0.0 through 2.0.3
Description The issue involves multiple cross-site scripting (XSS) vulnerabilities that allow remote authenticated users to inject arbitrary web script or HTML. This can be achieved via hex-encoded values in the QueueID parameter and Action parameters. The vulnerability can lead to a disruption of confidentiality, integrity, and availability of protected information and can be exploited remotely.
Recommendations For Open Ticket Request System (OTRS) versions 1.0.0 through 1.3.2, consider disabling the QueueID and Action parameters in the index.pl file until a patch is available. For Open Ticket Request System (OTRS) versions 2.0.0 through 2.0.3, consider disabling the QueueID and Action parameters in the index.pl file until a patch is available. As a temporary workaround, restrict access to the index.pl file to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-03039
BDU:2015-03040
BDU:2015-03041
CVE-2005-3894
DSA-973-1

Affected Products

Open Ticket Request System