CVE-2013-5587

Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.13, when MakeClicky is configured, allows remote attackers to inject arbitrary web script or HTML via a URL in a ticket. NOTE: this issue has been SPLIT from CVE-2013-3371 due to different affected versions.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:bestpractical:rt:4.0.0:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc2:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc3:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc4:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc5:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc6:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc7:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.0:rc8:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.1:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.1:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.1:rc2:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.2:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.2:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.2:rc2:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.3:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.3:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.3:rc2:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.4:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.5:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.5:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.6:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.7:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.7:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.8:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.8:rc1:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.8:rc2:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.9:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.10:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.11:*:*:*:*:*:*:*
cpe:2.3:a:bestpractical:rt:4.0.12:*:*:*:*:*:*:*

History

21 Nov 2024, 01:57

Type Values Removed Values Added
References () http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html - Patch () http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html - Patch
References () http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.html - Patch () http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.html - Patch
References () http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000228.html - Patch () http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000228.html - Patch
References () http://secunia.com/advisories/53505 - () http://secunia.com/advisories/53505 -
References () http://secunia.com/advisories/53522 - Vendor Advisory () http://secunia.com/advisories/53522 - Vendor Advisory
References () http://www.debian.org/security/2012/dsa-2670 - () http://www.debian.org/security/2012/dsa-2670 -

Information

Published : 2013-08-23 16:55

Updated : 2024-11-21 01:57


NVD link : CVE-2013-5587

Mitre link : CVE-2013-5587

CVE.ORG link : CVE-2013-5587


JSON object : View

Products Affected

bestpractical

  • rt
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')