264351
|
- |
|
otrs
|
otrs
|
The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4761
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264352
|
- |
|
otrs
|
otrs
|
Cross-site scripting (XSS) vulnerability in the rich-text-editor component in Open Ticket Request System (OTRS) before 3.0.0-beta2 allows remote authenticated users to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2010-4762
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264353
|
- |
|
otrs
|
otrs
|
The ACL-customer-status Ticket Type setting in Open Ticket Request System (OTRS) before 3.0.0-beta1 does not restrict the ticket options after an AJAX reload, which allows remote authenticated users …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4763
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264354
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.10, and 3.x before 3.0.3, does not present warnings about incoming encrypted e-mail messages that were based on revoked PGP or GPG keys, which makes it ea…
|
CWE-255
Credentials Management
|
CVE-2010-4764
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264355
|
- |
|
otrs
|
otrs
|
Race condition in the Kernel::System::Main::FileWrite method in Open Ticket Request System (OTRS) before 2.4.8 allows remote authenticated users to corrupt the TicketCounter.log data in opportunistic…
|
CWE-362
Race Condition
|
CVE-2010-4765
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264356
|
- |
|
otrs
|
otrs
|
The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially …
|
CWE-20
Improper Input Validation
|
CVE-2010-4766
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264357
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.3.6 does not properly handle e-mail messages in which the From line contains UTF-8 characters associated with diacritical marks and an invalid charset, whic…
|
CWE-20
Improper Input Validation
|
CVE-2010-4767
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264358
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intended queue access restrictions in opportunistic circ…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-4768
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264359
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.4 grants ticket access on the basis of single-digit substrings of the CustomerID value, which allows remote authenticated users to bypass intended access …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2009-5055
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
264360
|
- |
|
otrs
|
otrs
|
Open Ticket Request System (OTRS) before 2.4.0-beta2 does not properly enforce the move_into permission setting for a queue, which allows remote authenticated users to bypass intended access restrict…
|
CWE-20
Improper Input Validation
|
CVE-2009-5056
|
2011-03-22 13:00 |
2011-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|