Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pages to execute arbitrary private components via unspecified vectors.
Link | Tags |
---|---|
http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000228.html | patch vendor advisory mailing list |
http://www.osvdb.org/93610 | vdb entry |
http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.html | patch vendor advisory mailing list |
http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.html | patch vendor advisory mailing list |
http://secunia.com/advisories/53505 | third party advisory vendor advisory |
http://www.debian.org/security/2012/dsa-2670 | vendor advisory |
http://secunia.com/advisories/53522 | third party advisory vendor advisory |