CVE-2011-0456OS Command Injection in Otrs

Severity
7.5HIGHNVD
EPSS
3.0%
top 13.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMar 11
Latest updateMay 17

Description

webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."

CVSS vector

AV:N/AC:L/C:P/I:P/A:PExploitability: 10.0 | Impact: 6.4

Affected Packages2 packages

debiandebian/otrs2< otrs2 2.4.5-1 (bullseye)
NVDotrs/otrs2.3.4+28

🔴Vulnerability Details

2
GHSA
GHSA-c64g-c9hj-gqhg: webscript2022-05-17
OSV
CVE-2011-0456: webscript2011-03-11

📋Vendor Advisories

1
Debian
CVE-2011-0456: otrs2 - webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remot...2011

💬Community

2
Bugzilla
CVE-2011-0456 otrs: arbitrary command execution flaw2011-03-17
Bugzilla
CVE-2010-0438 CVE-2010-2080 CVE-2010-3476 CVE-2011-0456 otrs: multiple vulnerabilities [fedora-epel5]2010-09-20
CVE-2011-0456 — OS Command Injection in Otrs | cvebase