Skip to main content

Vendor/product archive

bestpractical / rt CVEs

Beta · best-effort

38 CVEs tagged to bestpractical / rt0 Critical, 1 High, 32 Medium, 5 Low, 0 Unrated.

CVE-2013-5587

Published Aug 23, 2013

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML v…

CVSS 2.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2013-3374

Published Aug 23, 2013

Unspecified vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13, when using the Apache::Session::File session store, allows remote attackers to obtai…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3373

Published Aug 23, 2013

CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3372

Published Aug 23, 2013

Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site script…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3371

Published Aug 23, 2013

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 3.8.3 through 3.8.16 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via th…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3370

Published Aug 23, 2013

Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remote attackers to have an unspeci…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3369

Published Aug 23, 2013

Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pages to execute arbitrary priva…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2013-3368

Published Aug 23, 2013

bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictabl…

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4733

Published Aug 23, 2013

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the Mo…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4884

Published Nov 11, 2012

Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files via unspecified vectors relat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4734

Published Nov 11, 2012

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and c…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4732

Published Nov 11, 2012

Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before 4.0.8, allows remote attackers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4730

Published Nov 11, 2012

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote authenticated users with ModifySelf or AdminUser privileges to inject arbitrary email headers and con…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-5093

Published Jun 4, 2012

Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated users to bypass intended access restrict…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5092

Published Jun 4, 2012

Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspecified vectors, a different vul…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4460

Published Jun 4, 2012

SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to execute arbitrary SQL commands by le…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4459

Published Jun 4, 2012

Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups, which allows remote authenticated users to bypass intended access restrictions…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-4458

Published Jun 4, 2012

Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabled, allows remote attackers to execute…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2085

Published Jun 4, 2012

Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote attackers to hijack the authentication of…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2084

Published Jun 4, 2012

Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to read (1) hashes of former passwords and (2) ticket correspondence history b…

CVSS 4.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2083

Published Jun 4, 2012

Multiple cross-site scripting (XSS) vulnerabilities in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allow remote attackers to inject arbitrary web script or…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2082

Published Jun 4, 2012

The vulnerable-passwords script in Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not update the password-hash algorithm for disabled user accounts, which…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 38 CVEsPage 1 of 2