|
|||||||
| osTicket SVA-2008-301 - Cross Site Scripting | ||||
|---|---|---|---|---|
| osTicket security vulnerability advisory | ||||
Category Unknown |
Affected Version 1.6 rc3 |
Priority 3 |
||
Status fixed |
Fixed Version 1.6 rc4 |
|||
Submitted 03-17-2008 |
||||
|
||||
|
|
|
|
|
|
osTicket SVA-2008-301 - Cross Site Scripting
osTicket security vulnerability advisory
osTicket prior to v1.6 RC4 fails to properly handle or/and escape user inputs prior to being displayed on tickets list/view pages, allowing a remote user to potentially inject arbitrary HTML and/or script code and possibly cause a remote denial of service attack. Format.striptags function used to clean inputs, fails to handle special cases of unclosed tags.
The security risk is moderately critical and for this reason we strongly recommend upgrading to the latest version (osTicket v1.6 RC4) as soon as possible. If you are unable to upgrade immediately, you should patch your current installation until you are able to do a complete upgrade. To temporarily patch osTicket v1.6 RC1-RC3 do the following * In class.format.php chage PHP Code:
PHP Code:
PHP Code:
PHP Code:
For more information and reference, please see http://www.securityfocus.com/bid/28144/ To contact osTicket developers regarding security related issues, please use the form at http://osticket.com/support/contact.php |
|
|
||
|
||
|
I have upgraded
Thank you |
|
|
||
|
||
|
Hi,
I have installed and using Osticket 1.6.rc4. I've been looking for if there is a security issue remaining for this version. Than I found this message and read. http://www.digitrustgroup.com/adviso...-osticket.html Then I started to look that this issue on internet. Then I found this article that says the issue about cross site scripting remaining on version 1.6 and the date which it was written 3 March 2008 same with the version 1.6.rc4 appeared on downloads page. So could you make a reply that a security issue remaning on version 1.6 or not. This is crucial for me that I want to use this software seriously. Thanks... |
|
|
||
|
||
|
Quote:
PHP Code:
|
![]() |
| Issue Tools |
|---|
Subscribe to this issue |