DEBIAN-CVE-2007-2524

Source
https://security-tracker.debian.org/tracker/CVE-2007-2524
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-2524.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2007-2524
Upstream
Downstream
Published
2007-05-08T23:19:00Z
Modified
2026-08-04T06:03:15Z
Summary
[none]
Details

Cross-site scripting (XSS) vulnerability in index.pl in Open Ticket Request System (OTRS) 2.0.x allows remote attackers to inject arbitrary web script or HTML via the Subaction parameter in an AgentTicketMailbox Action. NOTE: DEBIAN:DSA-1299 originally used this identifier for an ipsec-tools issue, but the proper identifier for the ipsec-tools issue is CVE-2007-1841.

References

Affected packages

Debian:11 / otrs2

Package

Name
otrs2
Purl
pkg:deb/debian/otrs2?arch=source&distro=bullseye

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
2.1.1-1

Affected versions

2.*
2.0.4p01-6
2.0.4p01-7
2.0.4p01-8
2.0.4p01-9
2.0.4p01-10
2.0.4p01-11
2.0.4p01-12
2.0.4p01-13
2.0.4p01-14
2.0.4p01-14.1
2.0.4p01-15
2.0.4p01-16
2.0.4p01-17
2.0.4p01-18
2.0.99beta1-1
2.0.99beta1-2

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2007-2524.json"