264861
|
- |
|
otrs
|
otrs
|
The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4763
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264862
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it ea…
|
CWE-255
Credentials Management
|
CVE-2010-4764
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264863
|
- |
|
otrs
|
otrs
|
Race condition in the Kernel::System::Main::FileWrite method in Open Ticket Request System (OTRS) before 2.4.8 allows remote authenticated users to corrupt the TicketCounter.log data in opportunistic…
|
CWE-362
Race Condition
|
CVE-2010-4765
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264864
|
- |
|
otrs
|
otrs
|
The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially …
|
CWE-20
Improper Input Validation
|
CVE-2010-4766
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264865
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.3.6 does not properly handle e-mail messages in which the From line contains UTF-8 characters associated with diacritical marks and an invalid charset, whic…
|
CWE-20
Improper Input Validation
|
CVE-2010-4767
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264866
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intended queue access restrictions in opportunistic circ…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4768
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264867
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5055
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264868
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrict…
|
CWE-20
Improper Input Validation
|
CVE-2009-5056
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264869
|
- |
|
otrs
|
otrs
|
The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to dec…
|
CWE-310
Cryptographic Issues
|
CVE-2009-5057
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264870
|
- |
|
otrs
|
otrs
|
Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTic…
|
CWE-79
Cross-site Scripting
|
CVE-2008-7275
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|