Record summary

CVE-2017-16921 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.26, an attacker who is logged into OTRS as an agent can manipulate form parameters (related to PGP) and execute arbitrary shell commands with the permissions of the OTRS or web server user.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

Proofs of concept

2

Catalogued exploits

ExploitDBOTRS 5.0.x/6.0.x - Remote Command Execution (1)ExploitDB exploitby Bæln0rnNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubSmarttfoxx/OTRS-4.0.1-6.0.1-Remote-Command-ExecutionRepository PoCby SmarttfoxxStars: 0Not analyzed2 files

6.5 KiB

GitHub

PoC details

References

6