OTRS Multiple Input Validation Vulnerabilities
BID:15537
CVE-2005-3893 | CVE-2005-3894 | CVE-2005-3895 |Info
OTRS Multiple Input Validation Vulnerabilities
| Bugtraq ID: | 15537 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-3893 CVE-2005-3894 CVE-2005-3895 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 22 2005 12:00AM |
| Updated: | Dec 20 2006 08:53PM |
| Credit: | Moritz Naumann IT Consulting & Services is credited with the discovery of these vulnerabilities. |
| Vulnerable: |
SuSE SUSE Linux Enterprise Server 8 SuSE Linux Enterprise Server 9 SuSE Linux Desktop 1.0 S.u.S.E. SuSE Linux School Server for i386 S.u.S.E. SUSE LINUX Retail Solution 8.0 S.u.S.E. SuSE Linux Openexchange Server 4.0 S.u.S.E. Open-Enterprise-Server 9.0 S.u.S.E. Novell Linux Desktop 9.0 S.u.S.E. Linux Professional 10.0 OSS S.u.S.E. Linux Professional 10.0 S.u.S.E. Linux Professional 9.3 x86_64 S.u.S.E. Linux Professional 9.3 S.u.S.E. Linux Professional 9.2 x86_64 S.u.S.E. Linux Professional 9.2 S.u.S.E. Linux Professional 9.1 x86_64 S.u.S.E. Linux Professional 9.1 S.u.S.E. Linux Professional 9.0 x86_64 S.u.S.E. Linux Professional 9.0 S.u.S.E. Linux Professional 8.2 S.u.S.E. Linux Personal 10.0 OSS S.u.S.E. Linux Personal 9.3 x86_64 S.u.S.E. Linux Personal 9.3 S.u.S.E. Linux Personal 9.2 x86_64 S.u.S.E. Linux Personal 9.2 S.u.S.E. Linux Personal 9.1 x86_64 S.u.S.E. Linux Personal 9.1 S.u.S.E. Linux Personal 9.0 x86_64 S.u.S.E. Linux Personal 9.0 S.u.S.E. Linux Personal 8.2 OTRS OTRS 2.0.3 OTRS OTRS 2.0.2 OTRS OTRS 2.0.1 OTRS OTRS 2.0 .0 OTRS OTRS 1.3.2 OTRS OTRS 1.0 .0 Joomla Joomla 1.0.3 Joomla Joomla 1.0.2 Joomla Joomla 1.0.1 Joomla Joomla 1.0 Debian Linux 3.1 sparc Debian Linux 3.1 s/390 Debian Linux 3.1 ppc Debian Linux 3.1 mipsel Debian Linux 3.1 mips Debian Linux 3.1 m68k Debian Linux 3.1 ia-64 Debian Linux 3.1 ia-32 Debian Linux 3.1 hppa Debian Linux 3.1 arm Debian Linux 3.1 amd64 Debian Linux 3.1 alpha Debian Linux 3.1 |
| Not Vulnerable: |
OTRS OTRS 2.0.4 OTRS OTRS 1.3.3 Joomla Joomla 1.0.4 |
Discussion
OTRS Multiple Input Validation Vulnerabilities
OTRS is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
The application is prone to multiple SQL-injection vulnerabilities, an HTML-injection vulnerability, and multiple cross-site scripting vulnerabilities.
OTRS is prone to multiple input-validation vulnerabilities. These issues are due to a failure in the application to properly sanitize user-supplied input.
The application is prone to multiple SQL-injection vulnerabilities, an HTML-injection vulnerability, and multiple cross-site scripting vulnerabilities.
Exploit / POC
OTRS Multiple Input Validation Vulnerabilities
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/index.pl?Action=Login&User=%27[SQL_HERE]
http://www.example.com/admin/index.pl?Action=AgentTicketPlain&ArticleID=1&TicketID=1%20[SQL_HERE]
http://www.example.com/admin/index.pl?Action=AgentTicketPlain&TicketID=1&ArticleID=1%20[SQL_HERE]
http://www.example.com/index.pl?QueueID=%22%3E%3Cscript%3Ealert('[XSS_HERE]')%3B%3C/script%3E%3Cx%20y=%22
http://www.example.com/index.pl?Action="><script>alert(document.title);</script><x%20"
No exploit is required.
The following proof of concept URI are available:
http://www.example.com/index.pl?Action=Login&User=%27[SQL_HERE]
http://www.example.com/admin/index.pl?Action=AgentTicketPlain&ArticleID=1&TicketID=1%20[SQL_HERE]
http://www.example.com/admin/index.pl?Action=AgentTicketPlain&TicketID=1&ArticleID=1%20[SQL_HERE]
http://www.example.com/index.pl?QueueID=%22%3E%3Cscript%3Ealert('[XSS_HERE]')%3B%3C/script%3E%3Cx%20y=%22
http://www.example.com/index.pl?Action="><script>alert(document.title);</script><x%20"
Solution / Fix
OTRS Multiple Input Validation Vulnerabilities
Solution:
The vendor has addressed these issues in the latest versions of the application. Users are advised to contact the vendor for further information.
Please see the referenced vendor advisories for more information and fixes.
OTRS OTRS 1.0 .0
Joomla Joomla 1.0
Joomla Joomla 1.0.1
Joomla Joomla 1.0.2
Joomla Joomla 1.0.3
OTRS OTRS 1.3.2
OTRS OTRS 2.0 .0
OTRS OTRS 2.0.1
OTRS OTRS 2.0.2
OTRS OTRS 2.0.3
Solution:
The vendor has addressed these issues in the latest versions of the application. Users are advised to contact the vendor for further information.
Please see the referenced vendor advisories for more information and fixes.
OTRS OTRS 1.0 .0
-
OTRS otrs-1.3.3-01.tar.gz
ftp://ftp.otrs.org/pub/otrs/otrs-1.3.3-01.tar.gz
Joomla Joomla 1.0
-
Joomla Joomla 1.0.4
http://developer.joomla.org/sf/frs/do/viewRelease/projects.joomla/frs. joomla_1_0.1_0_4
Joomla Joomla 1.0.1
-
Joomla Joomla 1.0.4
http://developer.joomla.org/sf/frs/do/viewRelease/projects.joomla/frs. joomla_1_0.1_0_4
Joomla Joomla 1.0.2
-
Joomla Joomla 1.0.4
http://developer.joomla.org/sf/frs/do/viewRelease/projects.joomla/frs. joomla_1_0.1_0_4
Joomla Joomla 1.0.3
-
Joomla Joomla 1.0.4
http://developer.joomla.org/sf/frs/do/viewRelease/projects.joomla/frs. joomla_1_0.1_0_4
OTRS OTRS 1.3.2
-
Debian otrs-doc-de_1.3.2p01-6_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/otrs/otrs-doc-de_1.3.2p 01-6_all.deb -
Debian otrs-doc-en_1.3.2p01-6_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/otrs/otrs-doc-en_1.3.2p 01-6_all.deb -
Debian otrs_1.3.2p01-6_all.deb
Debian GNU/Linux 3.1 alias sarge
http://security.debian.org/pool/updates/main/o/otrs/otrs_1.3.2p01-6_al l.deb -
OTRS otrs-1.3.3-01.tar.gz
ftp://ftp.otrs.org/pub/otrs/otrs-1.3.3-01.tar.gz
OTRS OTRS 2.0 .0
-
OTRS otrs-2.0.4-01.tar.gz
ftp://ftp.otrs.org/pub/otrs/otrs-2.0.4-01.tar.gz
OTRS OTRS 2.0.1
-
OTRS otrs-2.0.4-01.tar.gz
ftp://ftp.otrs.org/pub/otrs/otrs-2.0.4-01.tar.gz
OTRS OTRS 2.0.2
-
OTRS otrs-2.0.4-01.tar.gz
ftp://ftp.otrs.org/pub/otrs/otrs-2.0.4-01.tar.gz
OTRS OTRS 2.0.3
-
OTRS otrs-2.0.4-01.tar.gz
ftp://ftp.otrs.org/pub/otrs/otrs-2.0.4-01.tar.gz
References
OTRS Multiple Input Validation Vulnerabilities
References:
References:
- DSA-973-1 otrs -- several vulnerabilities (Debian)
- ezPortal/ztml Homepage (ezPortal/ztml)
- Joomla 1.0.4 Changelog (Joomla)
- OTRS 1.x/2.x Multiple Security Issues (Moritz Naumann)
- OTRS Homepage (OTRS)
- OTRS Security Advisory 2005-01 (OTRS)