CVE-2011-0456: OS Command Injection
webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-0456?
CVE-2011-0456 is classified as a high severity vulnerability due to its potential for remote command execution.
How do I fix CVE-2011-0456?
To fix CVE-2011-0456, upgrade to a version of OTRS later than 2.3.4 that addresses this command injection vulnerability.
What systems are affected by CVE-2011-0456?
CVE-2011-0456 affects Open Ticket Request System (OTRS) versions up to and including 2.3.4.
Can CVE-2011-0456 be exploited remotely?
Yes, CVE-2011-0456 can be exploited remotely by attackers to execute arbitrary commands on vulnerable systems.
What is a command injection vulnerability in CVE-2011-0456?
A command injection vulnerability like CVE-2011-0456 allows an attacker to execute arbitrary commands by injecting them into an application's input parameters.