CVE-2005-3894: XSS
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2005-3894?
CVE-2005-3894 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2005-3894?
To fix CVE-2005-3894, upgrade OTRS to version 2.0.4 or later where the vulnerabilities have been addressed.
Which versions of OTRS are affected by CVE-2005-3894?
CVE-2005-3894 affects OTRS versions 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3.
What types of attacks can be executed due to CVE-2005-3894?
CVE-2005-3894 allows remote authenticated users to perform cross-site scripting, potentially injecting arbitrary web scripts or HTML.
Who is impacted by CVE-2005-3894?
Remote authenticated users of the affected OTRS versions are impacted by CVE-2005-3894.