Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2005-3893
Description:Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.
Test IDs: 1.3.6.1.4.1.25623.1.0.56281  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2005-3893
BugTraq ID: 15537
http://www.securityfocus.com/bid/15537/
Bugtraq: 20051122 OTRS 1.x/2.x Multiple Security Issues (Google Search)
http://marc.info/?l=bugtraq&m=113272360804853&w=2
Debian Security Information: DSA-973 (Google Search)
http://www.debian.org/security/2006/dsa-973
http://lists.grok.org.uk/pipermail/full-disclosure/2005-November/039001.html
http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt
http://www.osvdb.org/21064
http://www.osvdb.org/21065
http://securitytracker.com/id?1015262
http://secunia.com/advisories/17685/
http://secunia.com/advisories/18101
http://secunia.com/advisories/18887
SuSE Security Announcement: SUSE-SR:2005:030 (Google Search)
http://www.novell.com/linux/security/advisories/2005_30_sr.html
http://www.vupen.com/english/advisories/2005/2535
XForce ISS Database: otrs-agentticketplain-sql-injection(23354)
https://exchange.xforce.ibmcloud.com/vulnerabilities/23354
XForce ISS Database: otrs-login-sql-injection(23352)
https://exchange.xforce.ibmcloud.com/vulnerabilities/23352




© 1998-2025 E-Soft Inc. All rights reserved.