Record summary

CVE-2012-4751 has a selected CVSS score of 4.3; EIP currently links 2 catalogued exploits.

Description

Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) Help Desk 2.4.x before 2.4.15, 3.0.x before 3.0.17, and 3.1.x before 3.1.11 allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with whitespace before a javascript: URL in the SRC attribute of an element, as demonstrated by an IFRAME element.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBOTRS Open Technology Real Services 3.1.8/3.1.9 - Cross-Site ScriptingExploitDB exploitby Mike EduardNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details
ExploitDBOTRS 3.1 - Persistent Cross-Site ScriptingExploitDB exploitby Mike EduardNot analyzed1 file

linked to 2 vulnerabilities

ExploitDB

PoC details

References

8