4.3
CVSSv2

CVE-2005-3894

Published: 29/11/2005 Updated: 20/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 435
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 up to and including 1.3.2 and 2.0.0 up to and including 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

otrs otrs 1.0.0

otrs otrs 1.3.2

otrs otrs 2.0.0

otrs otrs 2.0.1

otrs otrs 2.0.2

otrs otrs 2.0.3

Exploits

source: wwwsecurityfocuscom/bid/15537/info OTRS is prone to multiple input-validation vulnerabilities These issues are due to a failure in the application to properly sanitize user-supplied input The application is prone to multiple SQL-injection vulnerabilities, an HTML-injection vulnerability, and multiple cross-site scripting vu ...