Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2005-3895

Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.013
EPSS Ranking 78.4%
CVSS Severity
CVSS v2 Score 5.8
References
Products affected by CVE-2005-3895
  • Otrs » Otrs » Version: 1.0.0
    cpe:2.3:a:otrs:otrs:1.0.0
  • Otrs » Otrs » Version: 1.3.2
    cpe:2.3:a:otrs:otrs:1.3.2
  • Otrs » Otrs » Version: 2.0.0
    cpe:2.3:a:otrs:otrs:2.0.0
  • Otrs » Otrs » Version: 2.0.1
    cpe:2.3:a:otrs:otrs:2.0.1
  • Otrs » Otrs » Version: 2.0.2
    cpe:2.3:a:otrs:otrs:2.0.2
  • Otrs » Otrs » Version: 2.0.3
    cpe:2.3:a:otrs:otrs:2.0.3


Contact Us

Shodan ® - All rights reserved