Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2012-4751
Description:Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x before 3.1.11 allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with whitespace before a javascript: URL in the SRC attribute of an element, as demonstrated by an IFRAME element.
Test IDs: 1.3.6.1.4.1.25623.1.0.803939  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2012-4751
BugTraq ID: 56093
http://www.securityfocus.com/bid/56093
CERT/CC vulnerability note: VU#603276
http://www.kb.cert.org/vuls/id/603276
http://packetstormsecurity.org/files/117504/OTRS-3.1-Cross-Site-Scripting.html
SuSE Security Announcement: openSUSE-SU-2013:0145 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-01/msg00036.html




© 1998-2025 E-Soft Inc. All rights reserved.