[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

CVE-2018-7567 -- otrs2

ID: oval:org.secpod.oval:def:2000424Date: (C)2019-04-22   (M)2024-04-17
Class: VULNERABILITYFamily: unix




** DISPUTED ** In the Admin Package Manager in Open Ticket Request System 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are able to exploit a Blind Remote Code Execution vulnerability by loading a crafted opm file with an embedded CodeInstall element to execute a command on the server during package installation. NOTE: the vendor disputes this issue stating "the behaviour is as designed and needed for different packages to be installed", "there is a security warning if the package is not verified by OTRS Group", and "there is the possibility and responsibility of an admin to check packages before installation which is possible as they are not binary."

Platform:
Debian 8.x
Debian 9.x
Product:
otrs2
Reference:
CVE-2018-7567
CVE    1
CVE-2018-7567
CPE    3
cpe:/o:debian:debian_linux:8.x
cpe:/a:otrs:otrs
cpe:/o:debian:debian_linux:9.x

© SecPod Technologies