Lucene search

K
ubuntucveUbuntu.comUB:CVE-2012-2582
HistoryAug 23, 2012 - 12:00 a.m.

CVE-2012-2582

2012-08-2300:00:00
ubuntu.com
ubuntu.com
14

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.009

Percentile

82.8%

Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request
System (OTRS) Help Desk 2.4.x before 2.4.13, 3.0.x before 3.0.15, and 3.1.x
before 3.1.9, and OTRS ITSM 2.1.x before 2.1.5, 3.0.x before 3.0.6, and
3.1.x before 3.1.6, allow remote attackers to inject arbitrary web script
or HTML via an e-mail message body with (1) a Cascading Style Sheets (CSS)
expression property in the STYLE attribute of an arbitrary element or (2)
UTF-7 text in an HTTP-EQUIV=“CONTENT-TYPE” META element.

OSVersionArchitecturePackageVersionFilename
ubuntu11.04noarchotrs2< 2.4.9+dfsg1-3+squeeze3build0.11.04.1UNKNOWN

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

EPSS

0.009

Percentile

82.8%