CVE-2005-3895

Publication date 29 November 2005

Last updated 17 July 2025


Ubuntu priority

Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 through 2.0.3, when AttachmentDownloadType is set to inline, renders text/html e-mail attachments as HTML in the browser when the queue moderator attempts to download the attachment, which allows remote attackers to execute arbitrary web script or HTML. NOTE: this particular issue is referred to as XSS by some sources.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
otrs 7.04 feisty
Not affected
6.10 edgy
Not affected
6.06 LTS dapper
Not affected