FreshPorts - VuXML

This page displays vulnerability information about FreeBSD Ports.

The last vuln.xml file processed by FreshPorts is:

Revision:  366223
Date:      2014-08-26
Time:      16:36:41Z
Committer: rene

List all Vulnerabilities, by package

List all Vulnerabilities, by date

These are the vulnerabilities relating to the commit you have selected:

VuXML IDDescription
95a69d1a-52a5-11e2-a289-1c4bd681f0cfotrs -- XSS vulnerability in Firefox and Opera

OTRS Security Advisory reports:

This advisory covers vulnerabilities discovered in the OTRS core system. This is a variance of the XSS vulnerability, where an attacker could send a specially prepared HTML email to OTRS which would cause JavaScript code to be executed in your browser while displaying the email in Firefox and Opera. In this case this is achieved with an invalid HTML structure with nested tags.


Discovery 2012-08-30
Entry 2012-12-30
otrs
lt 3.1.10

CVE-2012-4600
http://www.otrs.com/open-source/community-news/security-advisories/security-advisory-2012-02/
6b575419-14cf-11df-a628-001517351c22otrs -- SQL injection

OTRS Security Advisory reports:

Missing security quoting for SQL statements allows agents and customers to manipulate SQL queries. So it's possible for authenticated users to inject SQL queries via string manipulation of statements.

A malicious user may be able to manipulate SQL queries to read or modify records in the database. This way it could also be possible to get access to more permissions (e. g. administrator permissions).

To use this vulnerability the malicious user needs to have a valid Agent- or Customer-session.


Discovery 2010-02-08
Entry 2010-02-08
Modified 2010-05-02
otrs
lt 2.4.7

CVE-2010-0438
http://otrs.org/advisory/OSA-2010-01-en/
49a6026a-52a3-11e2-a289-1c4bd681f0cfotrs -- XSS vulnerability in Internet Explorer

OTRS Security Advisory reports:

This advisory covers vulnerabilities discovered in the OTRS core system. Due to the XSS vulnerability in Internet Explorer an attacker could send a specially prepared HTML email to OTRS which would cause JavaScript code to be executed in your Internet Explorer while displaying the email.


Discovery 2012-08-22
Entry 2012-12-30
otrs
lt 3.1.9

CVE-2012-2582
http://www.otrs.com/open-source/community-news/security-advisories/security-advisory-2012-01/
13320091-52a6-11e2-a289-1c4bd681f0cfotrs -- XSS vulnerability

OTRS Security Advisory reports:

This advisory covers vulnerabilities discovered in the OTRS core system. This is a variance of the XSS vulnerability, where an attacker could send a specially prepared HTML email to OTRS which would cause JavaScript code to be executed in your browser while displaying the email. In this case this is achieved by using javascript source attributes with whitespaces.


Discovery 2012-10-16
Entry 2012-12-30
otrs
lt 3.1.11

CVE-2012-4751
http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2012-03/
http://www.kb.cert.org/vuls/id/603276
6b575419-14cf-11df-a628-001517351c22otrs -- SQL injection

OTRS Security Advisory reports:

Missing security quoting for SQL statements allows agents and customers to manipulate SQL queries. So it's possible for authenticated users to inject SQL queries via string manipulation of statements.

A malicious user may be able to manipulate SQL queries to read or modify records in the database. This way it could also be possible to get access to more permissions (e. g. administrator permissions).

To use this vulnerability the malicious user needs to have a valid Agent- or Customer-session.


Discovery 2010-02-08
Entry 2010-02-08
Modified 2010-05-02
otrs
lt 2.4.7

CVE-2010-0438
http://otrs.org/advisory/OSA-2010-01-en/
eae8e3cf-9dfe-11e2-ac7f-001fd056c417otrs -- Information disclosure and Data manipulation

The OTRS Project reports:

An attacker with a valid agent login could manipulate URLs in the object linking mechanism to see titles of tickets and other objects that are not obliged to be seen. Furthermore, links to objects without permission can be placed and removed.


Discovery 2013-04-02
Entry 2013-04-05
otrs
lt 3.1.14

CVE-2013-2625
http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2013-01/