5.8
CVSSv2

CVE-2005-3895

Published: 29/11/2005 Updated: 20/07/2017
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Open Ticket Request System (OTRS) 1.0.0 up to and including 1.3.2 and 2.0.0 up to and including 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote malicious users to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources.

Vulnerable Product Search on Vulmon Subscribe to Product

otrs otrs 1.3.2

otrs otrs 2.0.0

otrs otrs 2.0.1

otrs otrs 2.0.2

otrs otrs 1.0.0

otrs otrs 2.0.3