Page 20 of 149 results (0.009 seconds)

CVSS: 8.8EPSS: 0%CPEs: 5EXPL: 0

In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is capable of opening a specific URL in a browser to gain administrative privileges / full access. Afterward, all system settings can be read and changed. The URLs in question contain index.pl?Action=Installer with ;Subaction=Intro or ;Subaction=Start or ;Subaction=System appended at the end. En Open Ticket Request System (OTRS) versión 3.3.x hasta la versión 3.3.16, versión 4.x hasta 4.0.23 y versión 5.x hasta la versión 5.0.19, un atacante con permiso de agente es capaz de abrir una URL específica en un navegador para alcanzar privilegios administrativos y acceso completo. • http://www.debian.org/security/2017/dsa-3876 https://packetstormsecurity.com/files/142862/OTRS-Install-Dialog-Disclosure.html https://www.otrs.com/security-advisory-2017-03-security-update-otrs-versions • CWE-269: Improper Privilege Management •

CVSS: 6.1EPSS: 0%CPEs: 1EXPL: 1

Open Ticket Request System (OTRS) 3.3.9 has XSS in index.pl?Action=AgentStats requests, as demonstrated by OrderBy=[XSS] and Direction=[XSS] attacks. NOTE: this CVE may have limited relevance because it represents a 2017 discovery of an issue in software from 2014. The 3.3.20 release, for example, is not affected. Open Ticket Request System (OTRS) 3.3.9 tiene XSS en las peticiones index.pl? • http://code610.blogspot.com/2017/05/turnkey-feat-otrs.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 6.1EPSS: 0%CPEs: 133EXPL: 0

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.3.x before 3.3.16, 4.0.x before 4.0.19, and 5.0.x before 5.0.14 allows remote attackers to inject arbitrary web script or HTML via a crafted attachment. Vulnerabilidad de XSS en Open Ticket Request System (OTRS) 3.3.x en versiones anteriores a 3.3.16, 4.0.x en versiones anteriores a 4.0.19 y 5.0.x en versiones anteriores a 5.0.14 permite a atacantes remotos inyectar secuencias de comandos web o HTML arbitrarios a través de un adjunto manipulado. • http://www.securityfocus.com/bid/94141 https://www.otrs.com/security-advisory-2016-02-security-update-otrs • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.4EPSS: 0%CPEs: 30EXPL: 0

Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters. Múltiples vulnerabilidades de inyección SQL en el paquete FAQ 2.x en versiones anteriores a 2.3.6, 4.x en versiones anteriores a 4.0.5 y 5.x en versiones anteriores a 5.0.5 en Open Ticket Request System (OTRS) permiten a atacantes remotos ejecutar comandos SQL arbitrarios a través de parámetros de búsqueda manipulados. • http://www.securityfocus.com/bid/93019 https://github.com/OTRS/FAQ/commit/3700f75c67f6ed1d39bc213445c6d12a458e1af9 https://github.com/OTRS/FAQ/commit/8c9d63bd0297adda760330805c31afc130861557 https://github.com/OTRS/FAQ/commit/b805703e7b7725d1f3040bb626a4c4dd845ee9e3 https://www.otrs.com/security-advisory-2016-01-security-update-otrs-faq-package • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVSS: 6.0EPSS: 0%CPEs: 31EXPL: 0

The GenericInterface in OTRS Help Desk 3.2.x before 3.2.17, 3.3.x before 3.3.11, and 4.0.x before 4.0.3 allows remote authenticated users to access and modify arbitrary tickets via unspecified vectors. GenericInterface en OTRS Help Desk 3.2.x anterior a 3.2.17, 3.3.x anterior a 3.3.11 y 4.0.x anterior a 4.0.3 permiten a usuarios remotos autenticados acceder y modificar tickets arbitrarios a través de vectores sin especificar. • http://advisories.mageia.org/MGASA-2015-0031.html http://secunia.com/advisories/59875 http://secunia.com/advisories/62188 http://secunia.com/advisories/62662 http://www.mandriva.com/security/advisories?name=MDVSA-2015:043 https://www.otrs.com/security-advisory-2014-06-incomplete-access-control • CWE-264: Permissions, Privileges, and Access Controls •