CVE-2012-2582
Summary
| CVE | CVE-2012-2582 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-08-23 10:32:00 UTC |
| Updated | 2013-03-22 03:10:00 UTC |
| Description | Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and 3.1.x before 3.1.6, allow remote attackers to inject arbitrary web script or HTML via an e-mail message body with (1) a Cascading Style Sheets (CSS) expression property in the STYLE attribute of an arbitrary element or (2) UTF-7 text in an HTTP-EQUIV="CONTENT-TYPE" META element. |
Risk And Classification
Problem Types: CWE-79
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Otrs | Otrs | 2.4.0 | beta1 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta2 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta3 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta4 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta5 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta6 | All | All |
| Application | Otrs | Otrs | 2.4.1 | All | All | All |
| Application | Otrs | Otrs | 2.4.10 | All | All | All |
| Application | Otrs | Otrs | 2.4.11 | All | All | All |
| Application | Otrs | Otrs | 2.4.12 | All | All | All |
| Application | Otrs | Otrs | 2.4.2 | All | All | All |
| Application | Otrs | Otrs | 2.4.3 | All | All | All |
| Application | Otrs | Otrs | 2.4.4 | All | All | All |
| Application | Otrs | Otrs | 2.4.5 | All | All | All |
| Application | Otrs | Otrs | 2.4.6 | All | All | All |
| Application | Otrs | Otrs | 2.4.7 | All | All | All |
| Application | Otrs | Otrs | 2.4.8 | All | All | All |
| Application | Otrs | Otrs | 2.4.9 | All | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta1 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta2 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta3 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta4 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta5 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta6 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta7 | All | All |
| Application | Otrs | Otrs | 3.0.1 | All | All | All |
| Application | Otrs | Otrs | 3.0.10 | All | All | All |
| Application | Otrs | Otrs | 3.0.11 | All | All | All |
| Application | Otrs | Otrs | 3.0.12 | All | All | All |
| Application | Otrs | Otrs | 3.0.13 | All | All | All |
| Application | Otrs | Otrs | 3.0.14 | All | All | All |
| Application | Otrs | Otrs | 3.0.2 | All | All | All |
| Application | Otrs | Otrs | 3.0.3 | All | All | All |
| Application | Otrs | Otrs | 3.0.4 | All | All | All |
| Application | Otrs | Otrs | 3.0.5 | All | All | All |
| Application | Otrs | Otrs | 3.0.6 | All | All | All |
| Application | Otrs | Otrs | 3.0.7 | All | All | All |
| Application | Otrs | Otrs | 3.0.8 | All | All | All |
| Application | Otrs | Otrs | 3.0.9 | All | All | All |
| Application | Otrs | Otrs | 3.1.0 | All | All | All |
| Application | Otrs | Otrs | 3.1.1 | All | All | All |
| Application | Otrs | Otrs | 3.1.2 | All | All | All |
| Application | Otrs | Otrs | 3.1.3 | All | All | All |
| Application | Otrs | Otrs | 3.1.4 | All | All | All |
| Application | Otrs | Otrs | 3.1.5 | All | All | All |
| Application | Otrs | Otrs | 3.1.6 | All | All | All |
| Application | Otrs | Otrs | 3.1.7 | All | All | All |
| Application | Otrs | Otrs | 3.1.8 | All | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta1 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta2 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta3 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta4 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta5 | All | All |
| Application | Otrs | Otrs | 2.4.0 | beta6 | All | All |
| Application | Otrs | Otrs | 2.4.1 | All | All | All |
| Application | Otrs | Otrs | 2.4.10 | All | All | All |
| Application | Otrs | Otrs | 2.4.11 | All | All | All |
| Application | Otrs | Otrs | 2.4.12 | All | All | All |
| Application | Otrs | Otrs | 2.4.2 | All | All | All |
| Application | Otrs | Otrs | 2.4.3 | All | All | All |
| Application | Otrs | Otrs | 2.4.4 | All | All | All |
| Application | Otrs | Otrs | 2.4.5 | All | All | All |
| Application | Otrs | Otrs | 2.4.6 | All | All | All |
| Application | Otrs | Otrs | 2.4.7 | All | All | All |
| Application | Otrs | Otrs | 2.4.8 | All | All | All |
| Application | Otrs | Otrs | 2.4.9 | All | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta1 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta2 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta3 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta4 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta5 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta6 | All | All |
| Application | Otrs | Otrs | 3.0.0 | beta7 | All | All |
| Application | Otrs | Otrs | 3.0.1 | All | All | All |
| Application | Otrs | Otrs | 3.0.10 | All | All | All |
| Application | Otrs | Otrs | 3.0.11 | All | All | All |
| Application | Otrs | Otrs | 3.0.12 | All | All | All |
| Application | Otrs | Otrs | 3.0.13 | All | All | All |
| Application | Otrs | Otrs | 3.0.14 | All | All | All |
| Application | Otrs | Otrs | 3.0.2 | All | All | All |
| Application | Otrs | Otrs | 3.0.3 | All | All | All |
| Application | Otrs | Otrs | 3.0.4 | All | All | All |
| Application | Otrs | Otrs | 3.0.5 | All | All | All |
| Application | Otrs | Otrs | 3.0.6 | All | All | All |
| Application | Otrs | Otrs | 3.0.7 | All | All | All |
| Application | Otrs | Otrs | 3.0.8 | All | All | All |
| Application | Otrs | Otrs | 3.0.9 | All | All | All |
| Application | Otrs | Otrs | 3.1.0 | All | All | All |
| Application | Otrs | Otrs | 3.1.1 | All | All | All |
| Application | Otrs | Otrs | 3.1.2 | All | All | All |
| Application | Otrs | Otrs | 3.1.3 | All | All | All |
| Application | Otrs | Otrs | 3.1.4 | All | All | All |
| Application | Otrs | Otrs | 3.1.5 | All | All | All |
| Application | Otrs | Otrs | 3.1.6 | All | All | All |
| Application | Otrs | Otrs | 3.1.7 | All | All | All |
| Application | Otrs | Otrs | 3.1.8 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.5 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.5 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 2.1.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.0.5 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.0 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.1 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.2 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.3 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.4 | All | All | All |
| Application | Otrs | Otrs Itsm | 3.1.5 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Advisory 2012-01 | OTRS | CONFIRM | www.otrs.com | Vendor Advisory |
| openSUSE-SU-2012:1105-2: moderate: otrs: fixed security issue | SUSE | lists.opensuse.org | |
| Debian -- Security Information -- DSA-2536-1 otrs2 | DEBIAN | www.debian.org | |
| Vulnerability Note VU#582879 - Open Technology Real Services cross-site scripting vulnerability | CERT-VN | www.kb.cert.org | Exploit, US Government Resource |
| Security Advisory SA50513 - SUSE update for otrs - Secunia | SECUNIA | secunia.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.