Vulnerabilities > Bestpractical

DATE CVE VULNERABILITY TITLE RISK
2015-08-14 CVE-2015-5475 Cross-site Scripting vulnerability in Bestpractical Request Tracker
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.
4.3
2015-03-09 CVE-2015-1464 Improper Access Control vulnerability in multiple products
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.
network
low complexity
fedoraproject bestpractical CWE-284
6.4
2015-03-09 CVE-2015-1165 Information Exposure vulnerability in multiple products
RT (aka Request Tracker) 3.8.8 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to obtain sensitive RSS feed URLs and ticket data via unspecified vectors.
network
low complexity
debian fedoraproject bestpractical CWE-200
5.0
2015-03-09 CVE-2014-9472 Resource Management Errors vulnerability in multiple products
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a denial of service (CPU and disk consumption) via a crafted email.
7.1
2014-11-16 CVE-2013-3737 Information Exposure vulnerability in Bestpractical Request Tracker
The MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13, when using the file-based session store (Apache::Session::File) and certain authentication extensions, allows remote attackers to reuse unauthorized sessions and obtain user preferences and caches via unspecified vectors.
network
low complexity
bestpractical CWE-200
5.0
2014-07-15 CVE-2014-1474 Numeric Errors vulnerability in multiple products
Algorithmic complexity vulnerability in Email::Address::List before 0.02, as used in RT 4.2.0 through 4.2.2, allows remote attackers to cause a denial of service (CPU consumption) via a string without an address.
network
low complexity
bestpractical email CWE-189
5.0
2014-05-05 CVE-2013-3736 Cross-Site Scripting vulnerability in Bestpractical Request Tracker and Rt-Extension-Mobileui
Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the name of an attached file.
4.3
2013-08-23 CVE-2013-5587 Cross-Site Scripting vulnerability in Bestpractical RT
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket.
network
high complexity
bestpractical CWE-79
2.6
2013-08-23 CVE-2013-3374 Information Disclosure vulnerability in Request Tracker
Unspecified vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13, when using the Apache::Session::File session store, allows remote attackers to obtain sensitive information (user preferences and caches) via unknown vectors, related to a "limited session re-use."
network
bestpractical
4.3
2013-08-23 CVE-2013-3373 Code Injection vulnerability in Bestpractical RT
CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.
network
low complexity
bestpractical CWE-94
5.0