Bestpractical

Rt

48 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.35%
  • Veröffentlicht 23.08.2013 16:55:07
  • Zuletzt bearbeitet 29.04.2026 01:13:23

bin/rt in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows local users to overwrite arbitrary files via a symlink attack on a temporary file with predictable name.

  • EPSS 1.63%
  • Veröffentlicht 23.08.2013 16:55:06
  • Zuletzt bearbeitet 29.04.2026 01:13:23

Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows remote authenticated users with the ModifyTicket permission to delete tickets via unspecified vectors.

  • EPSS 1.82%
  • Veröffentlicht 11.11.2012 13:00:59
  • Zuletzt bearbeitet 16.06.2026 23:45:38

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to conduct a "confused deputy" attack to bypass the CSRF warning protection mechanism and cause victims to "modify arbitrary state" via unknown vectors related to...

  • EPSS 1.57%
  • Veröffentlicht 11.11.2012 13:00:59
  • Zuletzt bearbeitet 16.06.2026 23:45:50

Argument injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote attackers to create arbitrary files via unspecified vectors related to the GnuPG client.

  • EPSS 0.87%
  • Veröffentlicht 11.11.2012 13:00:59
  • Zuletzt bearbeitet 16.06.2026 23:45:38

Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versions before 4.0.8, allows remote attackers to hijack the authentication of users for requests that toggle ticket ...

  • EPSS 1.27%
  • Veröffentlicht 11.11.2012 13:00:59
  • Zuletzt bearbeitet 16.06.2026 23:45:38

Request Tracker (RT) 3.8.x before 3.8.15 and 4.0.x before 4.0.8 allows remote authenticated users with ModifySelf or AdminUser privileges to inject arbitrary email headers and conduct phishing attacks or obtain sensitive information via unknown vecto...

  • EPSS 2.09%
  • Veröffentlicht 04.06.2012 19:55:01
  • Zuletzt bearbeitet 16.06.2026 23:35:55

Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated users to bypass intended access restrictions and execute arbitrary code by leveraging access to a privileged ac...

  • EPSS 2.85%
  • Veröffentlicht 04.06.2012 19:55:01
  • Zuletzt bearbeitet 16.06.2026 23:35:55

Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges via unspecified vectors, a different vulnerability than CVE-2011-4458 and CVE-2011-5093.

  • EPSS 1.77%
  • Veröffentlicht 04.06.2012 19:55:01
  • Zuletzt bearbeitet 16.06.2026 23:34:55

SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to execute arbitrary SQL commands by leveraging access to a privileged account.

  • EPSS 1.02%
  • Veröffentlicht 04.06.2012 19:55:01
  • Zuletzt bearbeitet 16.06.2026 23:34:55

Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 does not properly disable groups, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging a group membership.