CVE-2010-4758
published 2011-03-18CVE-2010-4758: installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for…
PriorityP46low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.38%
29.3th percentile
installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
Affected
68 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | otrs2 | < otrs2 3.0.8+dfsg1-1 (bullseye) | otrs2 3.0.8+dfsg1-1 (bullseye) |
| otrs | otrs | <= 3.0.2 | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
| otrs | otrs | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_debian1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5prw-gxc9-p8gv: installer
ghsa_unreviewed·2022-05-17
CVE-2010-4758 [LOW] GHSA-5prw-gxc9-p8gv: installer
installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
OSV
CVE-2010-4758: installer
osv·2011-03-18·CVSS 1.9
CVE-2010-4758 [LOW] CVE-2010-4758: installer
installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
Debian
CVE-2010-4758: otrs2 - installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Ma...
vendor_debian·2010·CVSS 1.9
CVE-2010-4758 [LOW] CVE-2010-4758: otrs2 - installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Ma...
installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
Scope: local
bullseye: resolved (fixed in 3.0.8+dfsg1-1)
No detection rules found.
No public exploits indexed.
2011-03-18
Published