CVE-2008-7282
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2.2.6, when the CustomerPanelOwnSelection and CustomerGroupSupport options are enabled, allows remote authenticated users to bypass intended access restrictions, and perform certain (1) list and (2) write operations on queues, via unspecified vectors.
Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm en Open Ticket Request System (OTRS) anteriores a v2.2.6, cuando las opciones CustomerPanelOwnSelection y CustomerGroupSupport están habilitados, permite a usuarios remotos autenticados eludir las restricciones de acceso previsto, y llevar a cabo determinadas operaciones (1) list y (2) write en las colas, a través de vectores no especificados.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2011-03-18 CVE Reserved
- 2011-03-18 CVE Published
- 2024-09-16 CVE Updated
- 2024-09-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807 | X_refsource_confirm |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://bugs.otrs.org/show_bug.cgi?id=2696 | 2011-03-22 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | <= 2.2.5 Search vendor "Otrs" for product "Otrs" and version " <= 2.2.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta6 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta7 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 0.5 Search vendor "Otrs" for product "Otrs" and version "0.5" | beta8 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0 Search vendor "Otrs" for product "Otrs" and version "1.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0 Search vendor "Otrs" for product "Otrs" and version "1.0" | rc2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0 Search vendor "Otrs" for product "Otrs" and version "1.0" | rc3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0.0 Search vendor "Otrs" for product "Otrs" and version "1.0.0" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0.1 Search vendor "Otrs" for product "Otrs" and version "1.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.0.2 Search vendor "Otrs" for product "Otrs" and version "1.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1 Search vendor "Otrs" for product "Otrs" and version "1.1" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.0 Search vendor "Otrs" for product "Otrs" and version "1.1.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.0 Search vendor "Otrs" for product "Otrs" and version "1.1.0" | rc2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.1 Search vendor "Otrs" for product "Otrs" and version "1.1.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.2 Search vendor "Otrs" for product "Otrs" and version "1.1.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.3 Search vendor "Otrs" for product "Otrs" and version "1.1.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.1.4 Search vendor "Otrs" for product "Otrs" and version "1.1.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.0 Search vendor "Otrs" for product "Otrs" and version "1.2.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.0 Search vendor "Otrs" for product "Otrs" and version "1.2.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.0 Search vendor "Otrs" for product "Otrs" and version "1.2.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.1 Search vendor "Otrs" for product "Otrs" and version "1.2.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.2 Search vendor "Otrs" for product "Otrs" and version "1.2.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.3 Search vendor "Otrs" for product "Otrs" and version "1.2.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.2.4 Search vendor "Otrs" for product "Otrs" and version "1.2.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.0 Search vendor "Otrs" for product "Otrs" and version "1.3.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.1 Search vendor "Otrs" for product "Otrs" and version "1.3.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.2 Search vendor "Otrs" for product "Otrs" and version "1.3.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 1.3.3 Search vendor "Otrs" for product "Otrs" and version "1.3.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta5 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.0 Search vendor "Otrs" for product "Otrs" and version "2.0.0" | beta6 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.1 Search vendor "Otrs" for product "Otrs" and version "2.0.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.2 Search vendor "Otrs" for product "Otrs" and version "2.0.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.3 Search vendor "Otrs" for product "Otrs" and version "2.0.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.4 Search vendor "Otrs" for product "Otrs" and version "2.0.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.0.5 Search vendor "Otrs" for product "Otrs" and version "2.0.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.0 Search vendor "Otrs" for product "Otrs" and version "2.1.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.0 Search vendor "Otrs" for product "Otrs" and version "2.1.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.1 Search vendor "Otrs" for product "Otrs" and version "2.1.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.2 Search vendor "Otrs" for product "Otrs" and version "2.1.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.3 Search vendor "Otrs" for product "Otrs" and version "2.1.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.4 Search vendor "Otrs" for product "Otrs" and version "2.1.4" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.5 Search vendor "Otrs" for product "Otrs" and version "2.1.5" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.6 Search vendor "Otrs" for product "Otrs" and version "2.1.6" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.7 Search vendor "Otrs" for product "Otrs" and version "2.1.7" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.8 Search vendor "Otrs" for product "Otrs" and version "2.1.8" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.1.9 Search vendor "Otrs" for product "Otrs" and version "2.1.9" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta2 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta3 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | beta4 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.0 Search vendor "Otrs" for product "Otrs" and version "2.2.0" | rc1 |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.1 Search vendor "Otrs" for product "Otrs" and version "2.2.1" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.2 Search vendor "Otrs" for product "Otrs" and version "2.2.2" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.3 Search vendor "Otrs" for product "Otrs" and version "2.2.3" | - |
Affected
| ||||||
Otrs Search vendor "Otrs" | Otrs Search vendor "Otrs" for product "Otrs" | 2.2.4 Search vendor "Otrs" for product "Otrs" and version "2.2.4" | - |
Affected
|