NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
7006 | CVE-2008-7279 | The CustomerInterface component in Open Ticket Request System (OTRS) before 2.2.8 allows remote authenticated users to bypass intended access restrictions and access tickets of arbitrary customers via unspecified vectors. | 2 | 6.5 | Medium | 2017-01-03 | 2011-03-22 | View | |
7007 | CVE-2008-7280 | Kernel/System/EmailParser.pm in PostmasterPOP3.pl in Open Ticket Request System (OTRS) before 2.2.7 does not properly handle e-mail messages containing malformed UTF-8 characters, which allows remote attackers to cause a denial of service (e-mail retrieval outage) via a crafted message. | 2 | 5 | Medium | 2017-01-03 | 2011-03-22 | View | |
7008 | CVE-2008-7281 | Open Ticket Request System (OTRS) before 2.2.7 sends e-mail containing a Bcc header field that lists the Blind Carbon Copy recipients, which allows remote attackers to obtain potentially sensitive e-mail address information by reading this field. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-22 | View | |
7009 | CVE-2008-7282 | Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2.2.6, when the CustomerPanelOwnSelection and CustomerGroupSupport options are enabled, allows remote authenticated users to bypass intended access restrictions, and perform certain (1) list and (2) write operations on queues, via unspecified vectors. | 2 | 4.6 | Medium | 2017-01-03 | 2011-03-22 | View | |
7010 | CVE-2008-7283 | Open Ticket Request System (OTRS) before 2.2.6, when customer group support is enabled, allows remote authenticated users to bypass intended access restrictions and perform web-interface updates to tickets by leveraging queue read permissions. | 2 | 6 | Medium | 2017-01-03 | 2011-03-22 | View |
Page 1402 of 17672, showing 5 records out of 88360 total, starting on record 7006, ending on 7010