VYPR
Unrated severityNVD Advisory· Published Nov 29, 2005· Updated Jun 16, 2026

CVE-2005-3895

CVE-2005-3895

Description

Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • OTRS/Otrs7 versions
    cpe:2.3:a:otrs:otrs:1.0.0:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:a:otrs:otrs:1.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:1.3.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.0.0:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.0.1:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.0.2:*:*:*:*:*:*:*
    • cpe:2.3:a:otrs:otrs:2.0.3:*:*:*:*:*:*:*
    • (no CPE)range: 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3

Patches

Vulnerability mechanics

References

14

News mentions

0

No linked articles in our index yet.