otrs kayıtları
otrs üreticisine ait 161 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %68,3
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')36
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor29
- CWE-20 Improper Input Validation18
- CWE-264 Permissions, Privileges, and Access Controls15
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
161 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2017-16921Kavram kanıtı | In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who iotrs · otrs · CWE-78 | Yüksek8,8 | — | %19,9 | 8 Ara 2017 |
39İzleyin | CVE-2022-4427İstismar yok | SQL Injection via OTRS Search APIotrs · otrs · CWE-20 | Kritik9,8 | — | %0,7 | 19 Ara 2022 |
39İzleyin | CVE-2024-23790İstismar yok | Missing file type check in avatar picture uploadotrs · otrs · CWE-20 | Kritik9,8 | — | %0,3 | 29 Oca 2024 |
38İzleyin | CVE-2016-5843İstismar yok | Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request Syotrs · faq · CWE-89 | Kritik9,4 | — | %3,2 | 16 Eyl 2016 |
36İzleyin | CVE-2017-16664İstismar yok | Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3otrs · otrs · CWE-94 | Yüksek8,8 | — | %2,5 | 21 Kas 2017 |
36İzleyin | CVE-2017-9324İstismar yok | In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is otrs · otrs · CWE-269 | Yüksek8,8 | — | %2,4 | 12 Haz 2017 |
36İzleyin | CVE-2017-17476İstismar yok | Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might aotrs · otrs · CWE-200 | Yüksek8,8 | — | %2,2 | 20 Ara 2017 |
36İzleyin | CVE-2017-14635İstismar yok | In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage otrs · otrs · CWE-20 | Yüksek8,8 | — | %1,9 | 21 Eyl 2017 |
36İzleyin | CVE-2018-14593İstismar yok | An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30.otrs · open ticket request system | Yüksek8,8 | — | %1,9 | 3 Ağu 2018 |
36İzleyin | CVE-2017-15864İstismar yok | In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like otrs · otrs | Yüksek8,8 | — | %1,8 | 16 Kas 2017 |
36İzleyin | CVE-2026-48188Kavram kanıtı | SQL Injection via MySQL Quote Methodotrs · otrs · CWE-20 | Kritik9,1 | — | %0,5 | 1 Haz 2026 |
36İzleyin | CVE-2023-5422İstismar yok | SSL Certificates are not checked for E-Mail Handlingotrs · otrs · CWE-295 | Kritik9,1 | — | %0,3 | 16 Eki 2023 |
35İzleyin | CVE-2013-4717İstismar yok | Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x beotrs · otrs · CWE-89 | Yüksek8,8 | — | %1,3 | 9 Ağu 2021 |
35İzleyin | CVE-2021-36100İstismar yok | Authenticated remote code executionotrs · otrs · CWE-78 | Yüksek8,8 | — | %1,3 | 21 Mar 2022 |
35İzleyin | CVE-2022-39051İstismar yok | Perl Code execution in Template Toolkitotrs · otrs · CWE-913 | Yüksek8,8 | — | %0,8 | 5 Eyl 2022 |
35İzleyin | CVE-2023-38060İstismar yok | Host header injection by attachments in web serviceotrs · otrs · CWE-20 | Yüksek8,8 | — | %0,7 | 24 Tem 2023 |
32İzleyin | CVE-2005-3893Kavram kanıtı | Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow reotrs · otrs | Yüksek7,5 | — | %7,2 | 29 Kas 2005 |
32İzleyin | CVE-2020-1773İstismar yok | Session / Password / Password token leakotrs · otrs · CWE-331 | Yüksek8,1 | — | %1,5 | 27 Mar 2020 |
32İzleyin | CVE-2023-2534İstismar yok | Information disclouse and DoS via websocket push eventsotrs · otrs · CWE-285 | Yüksek8,1 | — | %0,5 | 8 May 2023 |
32İzleyin | CVE-2024-43444İstismar yok | Passwords are written to Admin Log Moduleotrs ag · otrs · CWE-532 | Yüksek8,2 | — | %0,4 | 26 Ağu 2024 |
31İzleyin | CVE-2011-0456İstismar yok | webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified veotrs · otrs · CWE-78 | Yüksek7,5 | — | %3,0 | 11 Mar 2011 |
31İzleyin | CVE-2019-18180İstismar yok | Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g.otrs · otrs · CWE-835 | Yüksek7,5 | — | %2,6 | 5 Ara 2019 |
31İzleyin | CVE-2014-1471İstismar yok | SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x beforeotrs · otrs · CWE-89 | Yüksek7,5 | — | %1,8 | 4 Şub 2014 |
31İzleyin | CVE-2023-1250İstismar yok | Code execution through ACL creationotrs · otrs · CWE-20 | Yüksek7,8 | — | %0,3 | 20 Mar 2023 |
30İzleyin | CVE-2018-7567İstismar yok | In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are ablotrs · otrs · CWE-434 | Yüksek7,2 | — | %5,2 | 4 Mar 2018 |
- CVE-2017-1692141Planlayın
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who i
YüksekCVSS 8,8Kavram kanıtıEPSS %20otrs · otrs8 Ara 2017
- CVE-2022-442739İzleyin
SQL Injection via OTRS Search API
KritikCVSS 9,8İstismar yokEPSS %1otrs · otrs19 Ara 2022
- CVE-2024-2379039İzleyin
Missing file type check in avatar picture upload
KritikCVSS 9,8İstismar yokEPSS %0otrs · otrs29 Oca 2024
- CVE-2016-584338İzleyin
Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request Sy
KritikCVSS 9,4İstismar yokEPSS %3otrs · faq16 Eyl 2016
- CVE-2017-1666436İzleyin
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3
YüksekCVSS 8,8İstismar yokEPSS %2otrs · otrs21 Kas 2017
- CVE-2017-932436İzleyin
In Open Ticket Request System (OTRS) 3.3.x through 3.3.16, 4.x through 4.0.23, and 5.x through 5.0.19, an attacker with agent permission is
YüksekCVSS 8,8İstismar yokEPSS %2otrs · otrs12 Haz 2017
- CVE-2017-1747636İzleyin
Open Ticket Request System (OTRS) 4.0.x before 4.0.28, 5.0.x before 5.0.26, and 6.0.x before 6.0.3, when cookie support is disabled, might a
YüksekCVSS 8,8İstismar yokEPSS %2otrs · otrs20 Ara 2017
- CVE-2017-1463536İzleyin
In Open Ticket Request System (OTRS) 3.3.x before 3.3.18, 4.x before 4.0.25, and 5.x before 5.0.23, remote authenticated users can leverage
YüksekCVSS 8,8İstismar yokEPSS %2otrs · otrs21 Eyl 2017
- CVE-2018-1459336İzleyin
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.9, 5.0.x through 5.0.28, and 4.0.x through 4.0.30.
YüksekCVSS 8,8İstismar yokEPSS %2otrs · open ticket request system3 Ağu 2018
- CVE-2017-1586436İzleyin
In the Agent Frontend in Open Ticket Request System (OTRS) 3.3.x through 3.3.18, with a crafted URL it is possible to gain information like
YüksekCVSS 8,8İstismar yokEPSS %2otrs · otrs16 Kas 2017
- CVE-2026-4818836İzleyin
SQL Injection via MySQL Quote Method
KritikCVSS 9,1Kavram kanıtıEPSS %0otrs · otrs1 Haz 2026
- CVE-2023-542236İzleyin
SSL Certificates are not checked for E-Mail Handling
KritikCVSS 9,1İstismar yokEPSS %0otrs · otrs16 Eki 2023
- CVE-2013-471735İzleyin
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x be
YüksekCVSS 8,8İstismar yokEPSS %1otrs · otrs9 Ağu 2021
- CVE-2021-3610035İzleyin
Authenticated remote code execution
YüksekCVSS 8,8İstismar yokEPSS %1otrs · otrs21 Mar 2022
- CVE-2022-3905135İzleyin
Perl Code execution in Template Toolkit
YüksekCVSS 8,8İstismar yokEPSS %1otrs · otrs5 Eyl 2022
- CVE-2023-3806035İzleyin
Host header injection by attachments in web service
YüksekCVSS 8,8İstismar yokEPSS %1otrs · otrs24 Tem 2023
- CVE-2005-389332İzleyin
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow re
YüksekCVSS 7,5Kavram kanıtıEPSS %7otrs · otrs29 Kas 2005
- CVE-2020-177332İzleyin
Session / Password / Password token leak
YüksekCVSS 8,1İstismar yokEPSS %1otrs · otrs27 Mar 2020
- CVE-2023-253432İzleyin
Information disclouse and DoS via websocket push events
YüksekCVSS 8,1İstismar yokEPSS %1otrs · otrs8 May 2023
- CVE-2024-4344432İzleyin
Passwords are written to Admin Log Module
YüksekCVSS 8,2İstismar yokEPSS %0otrs ag · otrs26 Ağu 2024
- CVE-2011-045631İzleyin
webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified ve
YüksekCVSS 7,5İstismar yokEPSS %3otrs · otrs11 Mar 2011
- CVE-2019-1818031İzleyin
Improper Check for filenames with overly long extensions in PostMaster (sending in email) or uploading files (e.g.
YüksekCVSS 7,5İstismar yokEPSS %3otrs · otrs5 Ara 2019
- CVE-2014-147131İzleyin
SQL injection vulnerability in the StateGetStatesByType function in Kernel/System/State.pm in Open Ticket Request System (OTRS) 3.1.x before
YüksekCVSS 7,5İstismar yokEPSS %2otrs · otrs4 Şub 2014
- CVE-2023-125031İzleyin
Code execution through ACL creation
YüksekCVSS 7,8İstismar yokEPSS %0otrs · otrs20 Mar 2023
- CVE-2018-756730İzleyin
In the Admin Package Manager in Open Ticket Request System (OTRS) 5.0.0 through 5.0.24 and 6.0.0 through 6.0.1, authenticated admins are abl
YüksekCVSS 7,2İstismar yokEPSS %5otrs · otrs4 Mar 2018