CVE-2010-0438
Last modified
CVE-2010-0438 is a vulnerability of currently unknown severity. Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.. EPSS estimates a 1.93% chance of exploitation in the next 30 days.
Description
Multiple SQL injection vulnerabilities in Kernel/System/Ticket.pm in OTRS-Core in Open Ticket Request System (OTRS) 2.1.x before 2.1.9, 2.2.x before 2.2.9, 2.3.x before 2.3.5, and 2.4.x before 2.4.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Otrs | Otrs | 2.1.1 |
| Otrs | Otrs | 2.1.2 |
| Otrs | Otrs | 2.1.3 |
| Otrs | Otrs | 2.1.4 |
| Otrs | Otrs | 2.1.5 |
| Otrs | Otrs | 2.1.6 |
| Otrs | Otrs | 2.1.7 |
| Otrs | Otrs | 2.1.8 |
| Otrs | Otrs | 2.2.1 |
| Otrs | Otrs | 2.2.2 |
| Otrs | Otrs | 2.2.3 |
| Otrs | Otrs | 2.2.4 |
| Otrs | Otrs | 2.2.5 |
| Otrs | Otrs | 2.2.6 |
| Otrs | Otrs | 2.2.7 |
| Otrs | Otrs | 2.2.8 |
| Otrs | Otrs | 2.3.1 |
| Otrs | Otrs | 2.3.2 |
| Otrs | Otrs | 2.3.3 |
| Otrs | Otrs | 2.3.4 |
| Otrs | Otrs | 2.4.1 |
| Otrs | Otrs | 2.4.2 |
| Otrs | Otrs | 2.4.3 |
| Otrs | Otrs | 2.4.4 |
| Otrs | Otrs | 2.4.5 |
| Otrs | Otrs | 2.4.6 |
References
- http://otrs.org/advisory/OSA-2010-01-en/Vendor Advisory
- http://secunia.com/advisories/38507Vendor Advisory
- http://otrs.org/advisory/OSA-2010-01-en/Vendor Advisory
- http://secunia.com/advisories/38507Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2010-0438?
How severe is CVE-2010-0438?
How do I fix CVE-2010-0438?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2010
- CVE-2010-0432Multiple cross-site scripting (XSS) vulnerabilities in the A…
- CVE-2010-0433The kssl_keytab_is_available function in ssl/kssl.c in OpenS…
- CVE-2010-0434The ap_read_request function in server/protocol.c in the Apa…
- CVE-2010-0435The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise V…
- CVE-2010-0436Race condition in backend/ctrl.c in KDM in KDE Software Comp…
- CVE-2010-0437The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in…
- CVE-2010-0439Chip Salzenberg Deliver allows local users to cause a denial…
- CVE-2010-0440Cross-site scripting (XSS) vulnerability in +CSCOT+/translat…
- CVE-2010-0441Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before…
- CVE-2010-0442The bitsubstr function in backend/utils/adt/varbit.c in Post…
- CVE-2010-0443Unspecified vulnerability in Record Management Services (RMS…
- CVE-2010-0444HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10…
Are you affected by CVE-2010-0438?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
