Summary
This host is running Open Ticket Request System (OTRS) and is prone to multiple SQL injection vulnerabilities.
Impact
Successful exploitation will allow attackers to manipulate SQL queries to read or modify records in the database, could also allow access to more administrator permissions.
Impact Level: Application
Solution
Upgarde to Open Ticket Request System (OTRS) 2.1.9, 2.2.9, 2.3.5, 2.4.7 For updates refer to http://otrs.org/download/
Insight
The flaws are due to error in 'Kernel/System/Ticket.pm' in 'OTRS-Core'. It fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Affected
Open Ticket Request System (OTRS) version prior to 2.1.9, 2.2.9,2.3.5 and 2.4.7
Detection
Get the installed version of OTRS with the help of detect NVT and check the version is vulnerable or not.
References
Severity
Classification
-
CVE CVE-2010-0438 -
CVSS Base Score: 6.5
AV:N/AC:L/Au:S/C:P/I:P/A:P
Related Vulnerabilities
- @Mail 'MailType' Parameter Cross Site Scripting Vulnerability
- Admidio get_file.php Remote File Disclosure Vulnerability
- Apache Roller 'q' Parameter Cross Site Scripting Vulnerability
- 12Planet Chat Server one2planet.infolet.InfoServlet XSS
- appRain CMF 'uploadify.php' Remote Arbitrary File Upload Vulnerability