Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2011-1008

Опубликовано: 28 фев. 2011
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4

Описание

Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

ignored

end of life, was pending
karmic

ignored

end of life
lucid

DNE

maverick

DNE

natty

DNE

oneiric

DNE

precise

DNE

quantal

DNE

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

karmic

ignored

end of life
lucid

released

3.8.7-1ubuntu2.2
maverick

released

3.8.8-4ubuntu0.1
natty

released

3.8.10-1
oneiric

not-affected

precise

not-affected

quantal

DNE

Показывать по

Ссылки на источники

EPSS

Процентиль: 69%
0.0061
Низкий

4 Medium

CVSS2

Связанные уязвимости

nvd
почти 15 лет назад

Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.

debian
почти 15 лет назад

Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not ...

github
больше 3 лет назад

Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.

EPSS

Процентиль: 69%
0.0061
Низкий

4 Medium

CVSS2

Уязвимость CVE-2011-1008