Required CVE Record Information
Description
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 3.8.3 through 3.8.16 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the filename of an attachment.
References 7 Total
- lists.bestpractical.com: [rt-announce] 20130522 RT 3.8.17 released mailing-list
- lists.bestpractical.com: [rt-announce] 20130522 Security vulnerabilities in RT mailing-list
- lists.bestpractical.com: [rt-announce] 20130522 RT 4.0.13 released mailing-list
- osvdb.org: 93608 vdb-entry
- secunia.com: 53505 third-party-advisory
- debian.org: DSA-2670 vendor-advisory
- secunia.com: 53522 third-party-advisory
Updated:
This container includes required additional information provided by the CVE Program for this vulnerability.
References 7 Total
- lists.bestpractical.com: [rt-announce] 20130522 RT 3.8.17 released mailing-listx_transferred
- lists.bestpractical.com: [rt-announce] 20130522 Security vulnerabilities in RT mailing-listx_transferred
- lists.bestpractical.com: [rt-announce] 20130522 RT 4.0.13 released mailing-listx_transferred
- osvdb.org: 93608 vdb-entryx_transferred
- secunia.com: 53505 third-party-advisoryx_transferred
- debian.org: DSA-2670 vendor-advisoryx_transferred
- secunia.com: 53522 third-party-advisoryx_transferred