Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Open Ticket Request System (OTRS) index.php 多个SQL注入漏洞
Vulnerability Description
OpenTRS是一款免费的开源的订票系统,它具有电子邮件、电话等接口功能。 Open Ticket Request System (OTRS) 1.0.0至1.3.2及2.0.0至2.0.3的index.php存在多个SQL注入漏洞,可让远程攻击者通过(1)Login操作中的user参数,以及通过AgentTicketPlain操作的(2) TicketID和(3) ArticleID参数远程认证的用户,执行任意SQL命令。
CVSS Information
N/A
Vulnerability Type
N/A