Bug#340352: otrs: Multiple SQL injection and Cross-Site-Scripting vulnerabilities

2006-02-14 Thread Torsten Werner
Hi Martin, Martin Schulze wrote: > +- SoryBy => 'Age', # > Owner|CustomerID|State|Ticket|Queue|Priority|Age > ++ SortBy => 'Age', # > Owner|CustomerID|State|Ticket|Queue|Priority|Age > > Could you... err... explain the change? I have obviously missed that change. I do

Bug#340352: otrs: Multiple SQL injection and Cross-Site-Scripting vulnerabilities

2006-02-13 Thread Martin Schulze
Torsten Werner wrote: > Moritz Muehlenhoff wrote: > > What's the status of an update for stable? > > > I have provide a fix over 2 months ago but I did not hear anything from > the security team. Hmm. I only find my complaints but no response from you. However, the packages on master are bette

Bug#340352: otrs: Multiple SQL injection and Cross-Site-Scripting vulnerabilities

2006-02-13 Thread Torsten Werner
Moritz Muehlenhoff wrote: > What's the status of an update for stable? I have provide a fix over 2 months ago but I did not hear anything from the security team. Regards, Torsten begin:vcard fn:Torsten Werner n:Werner;Torsten email;internet:[EMAIL PROTECTED] x-mozilla-html:FALSE url:http://www.

Bug#340352: otrs: Multiple SQL injection and Cross-Site-Scripting vulnerabilities

2006-02-10 Thread Moritz Muehlenhoff
Torsten Werner wrote: > > OTRS is vulnerable to several SQL injection and Cross-Site-Scripting > > vulnerabilities. Please see here for more information: > > http://otrs.org/advisory/OSA-2005-01-en/ > > http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt > > > > The new upstream version 1.3.3 fi

Bug#340352: otrs: Multiple SQL injection and Cross-Site-Scripting vulnerabilities

2005-11-22 Thread Torsten Werner
Moritz Muehlenhoff schrieb: > OTRS is vulnerable to several SQL injection and Cross-Site-Scripting > vulnerabilities. Please see here for more information: > http://otrs.org/advisory/OSA-2005-01-en/ > http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt > > The new upstream version 1.3.3 fixes al

Bug#340352: otrs: Multiple SQL injection and Cross-Site-Scripting vulnerabilities

2005-11-22 Thread Moritz Muehlenhoff
Package: otrs Severity: grave Tags: security Justification: user security hole OTRS is vulnerable to several SQL injection and Cross-Site-Scripting vulnerabilities. Please see here for more information: http://otrs.org/advisory/OSA-2005-01-en/ http://moritz-naumann.com/adv/0007/otrsmulti/0007.txt