First published: Fri Mar 11 2011(Updated: )
webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
OTRS | =2.1.3 | |
OTRS | =2.2.4 | |
OTRS | =2.2.5 | |
OTRS | =2.1.8 | |
OTRS | =2.1.5 | |
OTRS | =2.1.2 | |
OTRS | =2.0.3 | |
OTRS | =2.2.6 | |
OTRS | =2.3.3 | |
OTRS | =2.2.2 | |
OTRS | =2.3.1 | |
OTRS | =2.0.5 | |
OTRS | =2.2.9 | |
OTRS | =2.1.6 | |
OTRS | =1.3.2 | |
OTRS | =2.1.7 | |
OTRS | =2.0.4 | |
OTRS | =2.1.9 | |
OTRS | =2.2.7 | |
OTRS | =2.2.1 | |
OTRS | =2.1.4 | |
OTRS | <=2.3.4 | |
OTRS | =2.3.2 | |
OTRS | =2.1.1 | |
OTRS | =2.0.2 | |
OTRS | =2.0.1 | |
OTRS | =2.2.3 | |
OTRS | =1.3.3 | |
OTRS | =2.2.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0456 is classified as a high severity vulnerability due to its potential for remote command execution.
To fix CVE-2011-0456, upgrade to a version of OTRS later than 2.3.4 that addresses this command injection vulnerability.
CVE-2011-0456 affects Open Ticket Request System (OTRS) versions up to and including 2.3.4.
Yes, CVE-2011-0456 can be exploited remotely by attackers to execute arbitrary commands on vulnerable systems.
A command injection vulnerability like CVE-2011-0456 allows an attacker to execute arbitrary commands by injecting them into an application's input parameters.