CVE-2005-3893
OTRS 1.0.0-1.3.2 & 2.0.0-2.0.3 SQL Injection via Login & Authenticated Parameters
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2005-3893. PoCs published by Moritz Naumann.
AI-analyzed exploit summary The provided text describes multiple input-validation vulnerabilities in OTRS, including SQL injection and XSS, but does not contain functional exploit code. It references a generic SQL injection example without a full PoC.
Description
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) user parameter in the Login action, and remote authenticated users via the (2) TicketID and (3) ArticleID parameters of the AgentTicketPlain action.
Exploits (2)
The provided text describes multiple input-validation vulnerabilities in OTRS, including SQL injection and XSS, but does not contain functional exploit code. It references a generic SQL injection example without a full PoC.
The provided text describes SQL injection and XSS vulnerabilities in OTRS, with example URLs demonstrating potential attack vectors. It lacks executable exploit code but outlines the vulnerability details.