OTRS Unspecified Remote Command Execution Vulnerability
BID:46947
Info
OTRS Unspecified Remote Command Execution Vulnerability
| Bugtraq ID: | 46947 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-0456 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2011 12:00AM |
| Updated: | Mar 19 2015 08:09AM |
| Credit: | Takeshi Terada of Mitsui Bussan Secure Directions <br> |
| Vulnerable: |
S.u.S.E. openSUSE 11.2 OTRS OTRS 2.3.4 OTRS OTRS 2.2.9 OTRS OTRS 2.2.8 OTRS OTRS 2.2.6 OTRS OTRS 2.2.5 OTRS OTRS 2.2 OTRS OTRS 2.1.9 OTRS OTRS 2.1.8 OTRS OTRS 2.1.7 OTRS OTRS 2.1 OTRS OTRS 2.0.4 OTRS OTRS 2.0.3 OTRS OTRS 2.0.2 OTRS OTRS 2.0.1 OTRS OTRS 2.0 .0 OTRS OTRS 1.3.3 OTRS OTRS 1.3.2 OTRS OTRS 1.0 .0 OTRS OTRS 2.3.3 OTRS OTRS 2.3.2 OTRS OTRS 2.3.1 Apple Mac OS X Server 10.6.6 Apple Mac OS X Server 10.6.5 Apple Mac OS X Server 10.6.4 Apple Mac OS X Server 10.6.3 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac Os X Server 10.6.8 Apple Mac Os X Server 10.6.7 Apple Mac OS X Server 10.6 Apple Mac OS X 10.6.5 Apple Mac OS X 10.6.4 Apple Mac OS X 10.6.3 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.6 |
| Not Vulnerable: | |
Discussion
OTRS Unspecified Remote Command Execution Vulnerability
OTRS (Open Ticket Request System) is prone to an unspecified remote command-execution vulnerability because it fails to sanitize user-supplied input. This issue occurs in the webserver.
An attacker can exploit this issue to execute arbitrary commands with the privileges of the webserver; this may aid in further attacks.
Technical details are currently unavailable. We will update this BID as soon as more information emerges.
OTRS 2.3.4 and earlier versions are affected.
OTRS (Open Ticket Request System) is prone to an unspecified remote command-execution vulnerability because it fails to sanitize user-supplied input. This issue occurs in the webserver.
An attacker can exploit this issue to execute arbitrary commands with the privileges of the webserver; this may aid in further attacks.
Technical details are currently unavailable. We will update this BID as soon as more information emerges.
OTRS 2.3.4 and earlier versions are affected.
Exploit / POC
OTRS Unspecified Remote Command Execution Vulnerability
Attackers would likely exploit this issue via a browser.
Attackers would likely exploit this issue via a browser.
Solution / Fix
OTRS Unspecified Remote Command Execution Vulnerability
Solution:
Updates are available. Please see the references for details.
Apple Mac Os X Server 10.6.8
Solution:
Updates are available. Please see the references for details.
Apple Mac Os X Server 10.6.8
-
Apple SecUpdSrvr2011-006.dmg
http://www.apple.com/support/downloads/
References
OTRS Unspecified Remote Command Execution Vulnerability
References:
References:
- JVN#73162541 OTRS vulnerable to OS command injection (JPCERT/CC)
- OTRS Homepage (OTRS)