Описание
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
esm-infra-legacy/trusty | DNE | |
lucid | not-affected | |
precise | not-affected | |
precise/esm | DNE | precise was not-affected |
quantal | DNE | |
raring | DNE | |
saucy | DNE | |
trusty | DNE | |
trusty/esm | DNE |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | 4.0.19-1 |
esm-apps/xenial | not-affected | 4.0.19-1 |
esm-infra-legacy/trusty | DNE | trusty/esm was DNE [trusty was not-affected [4.0.19-1]] |
lucid | DNE | |
precise | ignored | end of life |
precise/esm | DNE | precise was needed |
quantal | ignored | end of life |
raring | ignored | end of life |
saucy | not-affected | 4.0.13-1 |
trusty | not-affected | 4.0.19-1 |
Показывать по
Ссылки на источники
2.6 Low
CVSS2
Связанные уязвимости
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x b ...
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.
2.6 Low
CVSS2