CVE-2017-16664
https://notcve.org/view.php?id=CVE-2017-16664
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user via URL manipulation. Existe inyección de código en Kernel/System/Spelling.pm en Open Ticket Request System (OTRS) 5 en versiones anteriores a la5.0.24; 4 en versiones anteriores a la 4.0.26 y 3.3 en versiones anteriores a la 3.3.20. En la interfaz del agente, un atacante remoto autenticado puede ejecutar comandos shell como el servidor web mediante la manipulación de URL. • https://lists.debian.org/debian-lts-announce/2017/12/msg00015.html https://www.debian.org/security/2017/dsa-4047 https://www.otrs.com/security-advisory-2017-07-security-update-otrs-framework • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2017-14635
https://notcve.org/view.php?id=CVE-2017-14635
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage statistics-write permissions to gain privileges via code injection. En OTRS (Open Ticket Request System) en versiones 3.3.x anteriores a la 3.3.18, 4.x anteriores a la 4.0.25 y 5.x anteriores a la 5.0.23, los usuarios autenticados remotos pueden utilizar los permisos de escritura de estadísticas para obtener privilegios mediante la inyección de código. • https://www.debian.org/security/2017/dsa-4021 https://www.otrs.com/security-advisory-2017-04-security-update-otrs-versions • CWE-20: Improper Input Validation •
CVE-2017-9324 – OTRS Install Dialog Disclosure
https://notcve.org/view.php?id=CVE-2017-9324
In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. The URLs in question contain index.pl?Action=Installer with ;Subaction=Intro or ;Subaction=Start or ;Subaction=System appended at the end. En Open Ticket Request System (OTRS) versión 3.3.x hasta la versión 3.3.16, versión 4.x hasta 4.0.23 y versión 5.x hasta la versión 5.0.19, un atacante con permiso de agente es capaz de abrir una URL específica en un navegador para alcanzar privilegios administrativos y acceso completo. • http://www.debian.org/security/2017/dsa-3876 https://packetstormsecurity.com/files/142862/OTRS-Install-Dialog-Disclosure.html https://www.otrs.com/security-advisory-2017-03-security-update-otrs-versions • CWE-269: Improper Privilege Management •
CVE-2016-9139
https://notcve.org/view.php?id=CVE-2016-9139
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment. Vulnerabilidad de XSS en Open Ticket Request System (OTRS) 3.3.x en versiones anteriores a 3.3.16, 4.0.x en versiones anteriores a 4.0.19 y 5.0.x en versiones anteriores a 5.0.14 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de un adjunto manipulado. • http://www.securityfocus.com/bid/94141 https://www.otrs.com/security-advisory-2016-02-security-update-otrs • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •
CVE-2014-9324
https://notcve.org/view.php?id=CVE-2014-9324
The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before 3.3.11, and 4.0.x before 4.0.3 allows remote authenticated users to access and modify arbitrary tickets via unspecified vectors. GenericInterface en OTRS Help Desk 3.2.x anterior a 3.2.17, 3.3.x anterior a 3.3.11 y 4.0.x anterior a 4.0.3 permiten a usuarios remotos autenticados acceder y modificar tickets arbitrarios a través de vectores sin especificar. • http://advisories.mageia.org/MGASA-2015-0031.html http://secunia.com/advisories/59875 http://secunia.com/advisories/62188 http://secunia.com/advisories/62662 http://www.mandriva.com/security/advisories?name=MDVSA-2015:043 https://www.otrs.com/security-advisory-2014-06-incomplete-access-control • CWE-264: Permissions, Privileges, and Access Controls •