OTRS Core System Multiple Unspecified SQL Injection Vulnerabilities
BID:38146
Info
OTRS Core System Multiple Unspecified SQL Injection Vulnerabilities
| Bugtraq ID: | 38146 |
| Class: | Input Validation Error |
| CVE: |
CVE-2010-0438 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2010 12:00AM |
| Updated: | Aug 02 2010 07:05PM |
| Credit: | CESICAT |
| Vulnerable: |
S.u.S.E. openSUSE 11.2 S.u.S.E. openSUSE 11.1 S.u.S.E. openSUSE 11.0 OTRS OTRS 2.4.6 OTRS OTRS 2.3.4 OTRS OTRS 2.2.8 OTRS OTRS 2.1.8 Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 |
| Not Vulnerable: |
OTRS OTRS 2.4.7 OTRS OTRS 2.3.5 OTRS OTRS 2.2.9 OTRS OTRS 2.1.9 |
Discussion
OTRS Core System Multiple Unspecified SQL Injection Vulnerabilities
OTRS (Open Ticket Request System) is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OTRS 2.4.x, 2.3.x, 2.2.x, and 2.1.x are vulnerable.
OTRS (Open Ticket Request System) is prone to multiple SQL-injection vulnerabilities because it fails to sufficiently sanitize user-supplied data before using it in SQL queries.
Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
OTRS 2.4.x, 2.3.x, 2.2.x, and 2.1.x are vulnerable.
Exploit / POC
OTRS Core System Multiple Unspecified SQL Injection Vulnerabilities
Attackers can use a browser to exploit these issues.
Attackers can use a browser to exploit these issues.
Solution / Fix
OTRS Core System Multiple Unspecified SQL Injection Vulnerabilities
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Debian Linux 5.0 hppa
Debian Linux 5.0 ia-64
Debian Linux 5.0 m68k
Debian Linux 5.0 arm
Debian Linux 5.0 armel
Debian Linux 5.0
Debian Linux 5.0 alpha
Debian Linux 5.0 amd64
Debian Linux 5.0 ia-32
Debian Linux 5.0 mips
Debian Linux 5.0 s/390
Debian Linux 5.0 mipsel
Debian Linux 5.0 powerpc
Debian Linux 5.0 sparc
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Debian Linux 5.0 hppa
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 ia-64
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 m68k
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 arm
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 armel
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 alpha
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 amd64
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 ia-32
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 mips
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 s/390
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 mipsel
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 powerpc
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
Debian Linux 5.0 sparc
-
Debian otrs2_2.2.7-2lenny3_all.deb
http://security.debian.org/pool/updates/main/o/otrs2/otrs2_2.2.7-2lenn y3_all.deb
References
OTRS Core System Multiple Unspecified SQL Injection Vulnerabilities
References:
References:
- OTRS Homepage (OTRS )
- OTRS Security Advisory 2010-01 (OTRS)