CVE-2016-5843
Summary
| CVE | CVE-2016-5843 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2016-09-17 02:59:00 UTC |
| Updated | 2016-11-28 20:29:00 UTC |
| Description | Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Otrs | Faq | 2.0.1 | All | All | All |
| Application | Otrs | Faq | 2.0.2 | All | All | All |
| Application | Otrs | Faq | 2.0.3 | All | All | All |
| Application | Otrs | Faq | 2.0.4 | All | All | All |
| Application | Otrs | Faq | 2.0.5 | All | All | All |
| Application | Otrs | Faq | 2.0.6 | All | All | All |
| Application | Otrs | Faq | 2.0.7 | All | All | All |
| Application | Otrs | Faq | 2.0.8 | All | All | All |
| Application | Otrs | Faq | 2.1.0 | All | All | All |
| Application | Otrs | Faq | 2.1.1 | All | All | All |
| Application | Otrs | Faq | 2.1.2 | All | All | All |
| Application | Otrs | Faq | 2.1.3 | All | All | All |
| Application | Otrs | Faq | 2.1.4 | All | All | All |
| Application | Otrs | Faq | 2.2.0 | All | All | All |
| Application | Otrs | Faq | 2.2.1 | All | All | All |
| Application | Otrs | Faq | 2.2.2 | All | All | All |
| Application | Otrs | Faq | 2.2.3 | All | All | All |
| Application | Otrs | Faq | 2.3.0 | All | All | All |
| Application | Otrs | Faq | 2.3.1 | All | All | All |
| Application | Otrs | Faq | 2.3.2 | All | All | All |
| Application | Otrs | Faq | 2.3.3 | All | All | All |
| Application | Otrs | Faq | 2.3.4 | All | All | All |
| Application | Otrs | Faq | 4.0.0 | All | All | All |
| Application | Otrs | Faq | 4.0.1 | All | All | All |
| Application | Otrs | Faq | 4.0.2 | All | All | All |
| Application | Otrs | Faq | 4.0.3 | All | All | All |
| Application | Otrs | Faq | 5.0.0 | All | All | All |
| Application | Otrs | Faq | 5.0.1 | All | All | All |
| Application | Otrs | Faq | 5.0.2 | All | All | All |
| Application | Otrs | Faq | 5.0.3 | All | All | All |
| Application | Otrs | Faq | 2.0.1 | All | All | All |
| Application | Otrs | Faq | 2.0.2 | All | All | All |
| Application | Otrs | Faq | 2.0.3 | All | All | All |
| Application | Otrs | Faq | 2.0.4 | All | All | All |
| Application | Otrs | Faq | 2.0.5 | All | All | All |
| Application | Otrs | Faq | 2.0.6 | All | All | All |
| Application | Otrs | Faq | 2.0.7 | All | All | All |
| Application | Otrs | Faq | 2.0.8 | All | All | All |
| Application | Otrs | Faq | 2.1.0 | All | All | All |
| Application | Otrs | Faq | 2.1.1 | All | All | All |
| Application | Otrs | Faq | 2.1.2 | All | All | All |
| Application | Otrs | Faq | 2.1.3 | All | All | All |
| Application | Otrs | Faq | 2.1.4 | All | All | All |
| Application | Otrs | Faq | 2.2.0 | All | All | All |
| Application | Otrs | Faq | 2.2.1 | All | All | All |
| Application | Otrs | Faq | 2.2.2 | All | All | All |
| Application | Otrs | Faq | 2.2.3 | All | All | All |
| Application | Otrs | Faq | 2.3.0 | All | All | All |
| Application | Otrs | Faq | 2.3.1 | All | All | All |
| Application | Otrs | Faq | 2.3.2 | All | All | All |
| Application | Otrs | Faq | 2.3.3 | All | All | All |
| Application | Otrs | Faq | 2.3.4 | All | All | All |
| Application | Otrs | Faq | 4.0.0 | All | All | All |
| Application | Otrs | Faq | 4.0.1 | All | All | All |
| Application | Otrs | Faq | 4.0.2 | All | All | All |
| Application | Otrs | Faq | 4.0.3 | All | All | All |
| Application | Otrs | Faq | 5.0.0 | All | All | All |
| Application | Otrs | Faq | 5.0.1 | All | All | All |
| Application | Otrs | Faq | 5.0.2 | All | All | All |
| Application | Otrs | Faq | 5.0.3 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fixed issue with not correctly quoted search parameters. · OTRS/FAQ@b805703 · GitHub | CONFIRM | github.com | Issue Tracking, Patch |
| Fixed issue with not correctly quoted search parameters. · OTRS/FAQ@3700f75 · GitHub | CONFIRM | github.com | Issue Tracking, Patch |
| Malformed Request | BID | www.securityfocus.com | |
| Security Advisory 2016-01: Security Update for OTRS FAQ package - otrs.com | CONFIRM | www.otrs.com | Vendor Advisory |
| Fixed issue with not correctly quoted search parameters. · OTRS/FAQ@8c9d63b · GitHub | CONFIRM | github.com | Issue Tracking, Patch |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.