264631
|
- |
|
otrs
|
otrs
|
Race condition in the Kernel::System::Main::FileWrite method in Open Ticket Request System (OTRS) before 2.4.8 allows remote authenticated users to corrupt the TicketCounter.log data in opportunistic…
|
CWE-362
Race Condition
|
CVE-2010-4765
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264632
|
- |
|
otrs
|
otrs
|
The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially …
|
CWE-20
Improper Input Validation
|
CVE-2010-4766
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264633
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.3.6 does not properly handle e-mail messages in which the From line contains UTF-8 characters associated with diacritical marks and an invalid charset, whic…
|
CWE-20
Improper Input Validation
|
CVE-2010-4767
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264634
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intended queue access restrictions in opportunistic circ…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4768
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264635
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5055
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264636
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrict…
|
CWE-20
Improper Input Validation
|
CVE-2009-5056
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264637
|
- |
|
otrs
|
otrs
|
The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to dec…
|
CWE-310
Cryptographic Issues
|
CVE-2009-5057
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264638
|
- |
|
otrs
|
otrs
|
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTic…
|
CWE-79
Cross-site Scripting
|
CVE-2008-7275
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264639
|
- |
|
otrs
|
otrs
|
Kernel/System/Web/Request.pm in Open Ticket Request System (OTRS) before 2.3.2 creates a directory under /tmp/ with 1274 permissions, which might allow local users to bypass intended access restricti…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-7276
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264640
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.3.0-beta4 checks for the rw permission, instead of the configured merge permission, during authorization of merge operations, which might allow remote authe…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2008-7277
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|