CVE-2010-4758
N/A
N/A
Summary
installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://bugs.otrs.org/show_bug.cgi?id=6302
- http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807
References
- http://bugs.otrs.org/show_bug.cgi?id=6302
- http://source.otrs.org/viewvc.cgi/otrs/CHANGES?revision=1.1807
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.