#!/usr/bin/python ''' Author: loneferret of Offensive Security Product: OTRS Open Technology Real Services Version: 3.1.4 (Windows) Vendor Site: http://www.otrs.com/en/ Timeline: 29 May 2012: Vulnerability reported to CERT 30 May 2012: Response received from CERT with disclosure date set to 20 Jul 2012 23 Jul 2012: Update from CERT: No response other than auto-reply from vendor 08 Aug 2012: Public Disclosure 22 Aug 2012: Update from CERT: vulnerability patched http://www.kb.cert.org/vuls/id/582879 http://www.otrs.com/en/open-source/community-news/security-advisories/security-advisory-2012-01/ Installed On: Windows Server 2003 SP2 Client Test OS: Window 7 Pro SP1 (x86) Browser Used: Internet Explorer 9 Injection Point: Body Injection Payload(s): 1: