CVE-2010-0438
CVE-2010-0438
Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
http://lists.opensuse.org/opensuse-security-announce/2010-08/msg00001.htmlhttp://otrs.org/advisory/OSA-2010-01-en/http://otrs.org/releases/2.4.7/http://secunia.com/advisories/38507http://secunia.com/advisories/38544http://source.otrs.org/viewvc.cgi/otrs/Kernel/System/Ticket.pm?view=loghttp://www.osvdb.org/62181http://www.otrs.org/news/2010/otrs_2-4-7/http://www.securityfocus.com/bid/38146