[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

249966

 
 

909

 
 

195636

 
 

282

Paid content will be excluded from the download.


Download | Alert*


CVE-2017-15864
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like database user and password.

CVE-2017-16664
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user via URL manipulation.

*OVAL
oval:org.secpod.oval:def:53195
CPE    9
cpe:/a:otrs:otrs
cpe:/a:otrs:otrs:3.3.6
cpe:/a:otrs:otrs:3.3.5
cpe:/a:otrs:otrs:3.3.4
...

© SecPod Technologies