Summary
The remote host is missing an update to otrs2
announced via advisory DSA 1298-1.
Solution
https://secure1.securityspace.com/smysecure/catid.html?in=DSA%201298-1
Insight
It was discovered that the Open Ticket Request System performs insufficient input sanitising for the Subaction parameter, which allows the injection of arbitrary web script code.
The oldstable distribution (sarge) doesn't include otrs2.
For the stable distribution (etch) this problem has been fixed in version 2.0.4p01-18.
The unstable distribution (sid) isn't affected by this problem.
We recommend that you upgrade your otrs2 package.
Severity
Classification
-
CVE CVE-2007-2524 -
CVSS Base Score: 4.3
AV:N/AC:M/Au:N/C:N/I:P/A:N
Related Vulnerabilities