Upstream information
Description
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3 allow remote authenticated users to inject arbitrary web script or HTML via (1) hex-encoded values in the QueueID parameter and (2) Action parameters.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 135006 SUSE Security Advisories:- SUSE-SR:2005:030, published Fri, 16 Dec 2005 16:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE LINUX 10.0 |
| |
| SuSE Linux 9.0 for AMD64 SuSE Linux 9.0 for IA32 |
| |
| SUSE LINUX 9.2 SUSE LINUX 9.3 |
|
