Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-3525

Опубликовано: 10 мая 2013
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author's claims.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:bestpractical:request_tracker:*:*:*:*:*:*:*:*
Версия до 4.0.9 (включая)
cpe:2.3:a:bestpractical:request_tracker:3.6.8:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.6.10:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.6.11:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.3:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.4:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.7:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.9:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.10:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.11:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.12:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.13:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.14:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.15:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:3.8.16:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:request_tracker:4.0.8:*:*:*:*:*:*:*

EPSS

Процентиль: 81%
0.01525
Низкий

7.5 High

CVSS2

Дефекты

CWE-89

Связанные уязвимости

ubuntu
больше 12 лет назад

SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author's claims.

debian
больше 12 лет назад

SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0. ...

github
больше 3 лет назад

** DISPUTED ** SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author's claims."

EPSS

Процентиль: 81%
0.01525
Низкий

7.5 High

CVSS2

Дефекты

CWE-89