Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2011-1008

Опубликовано: 28 фев. 2011
Источник: debian
EPSS Низкий

Описание

Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
request-tracker3.8fixed3.8.10-1package
request-tracker3.8fixed3.8.8-7+squeeze1squeezepackage
request-tracker3.6fixed3.6.7-5+lenny6lennypackage

EPSS

Процентиль: 69%
0.0061
Низкий

Связанные уязвимости

ubuntu
почти 15 лет назад

Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.

nvd
почти 15 лет назад

Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.

github
больше 3 лет назад

Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.

EPSS

Процентиль: 69%
0.0061
Низкий