Перейти к содержимому
Noroxi

Записи bestpractical

73 опубликованных записей вендора bestpractical.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
7
С записью об исправлении
83,6 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

73 записей
  • CVE-2017-5944
    36Наблюдать

    The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remo

    ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %

    bestpractical · request tracker3 июл. 2017 г.

  • CVE-2022-25801
    36Наблюдать

    Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    bestpractical · request tracker for incident response14 июл. 2022 г.

  • CVE-2022-25800
    36Наблюдать

    Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    bestpractical · request tracker for incident response14 июл. 2022 г.

  • CVE-2026-44231
    36Наблюдать

    RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    bestpractical · request tracker20 июл. 2026 г.

  • CVE-2017-5943
    35Наблюдать

    Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    bestpractical · request tracker3 июл. 2017 г.

  • CVE-2011-5092
    31Наблюдать

    Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges v

    ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %

    bestpractical · rt4 июн. 2012 г.

  • CVE-2013-3525
    31Наблюдать

    SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL comman

    ВысокаяCVSS 7,5Proof of conceptEPSS 3 %

    bestpractical · request tracker10 мая 2013 г.

  • CVE-2018-18898
    31Наблюдать

    The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorit

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    bestpractical · request tracker21 мар. 2019 г.

  • CVE-2021-38562
    31Наблюдать

    Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a

    ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %

    bestpractical · request tracker18 окт. 2021 г.

  • CVE-2023-41259
    30Наблюдать

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    bestpractical · request tracker3 нояб. 2023 г.

  • CVE-2023-41260
    30Наблюдать

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API call

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    bestpractical · request tracker3 нояб. 2023 г.

  • CVE-2023-45024
    30Наблюдать

    Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.

    ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %

    bestpractical · request tracker3 нояб. 2023 г.

  • CVE-2014-9472
    29Наблюдать

    The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a den

    ВысокаяCVSS 7,1Эксплойта нетEPSS 3 %

    debian · debian linux9 мар. 2015 г.

  • CVE-2011-4458
    28Наблюдать

    Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabl

    СредняяCVSS 6,8Эксплойта нетEPSS 3 %

    bestpractical · rt4 июн. 2012 г.

  • CVE-2013-3370
    28Наблюдать

    Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which all

    СредняяCVSS 6,8Эксплойта нетEPSS 2 %

    bestpractical · rt23 авг. 2013 г.

  • CVE-2011-5093
    27Наблюдать

    Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated u

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    bestpractical · rt4 июн. 2012 г.

  • CVE-2011-4460
    27Наблюдать

    SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    bestpractical · rt4 июн. 2012 г.

  • CVE-2011-2085
    27Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote at

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    bestpractical · rt4 июн. 2012 г.

  • CVE-2012-4732
    27Наблюдать

    Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other version

    СредняяCVSS 6,8Эксплойта нетEPSS 1 %

    bestpractical · rt11 нояб. 2012 г.

  • CVE-2015-1464
    26Наблюдать

    RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.

    СредняяCVSS 6,4Эксплойта нетEPSS 2 %

    fedoraproject · fedora9 мар. 2015 г.

  • CVE-2011-1686
    26Наблюдать

    Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc

    СредняяCVSS 6,5Эксплойта нетEPSS 1 %

    bestpractical · rt22 апр. 2011 г.

  • CVE-2012-6579
    25Наблюдать

    Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encrypti

    СредняяCVSS 6,4Эксплойта нетEPSS 1 %

    bestpractical · request tracker24 июл. 2013 г.

  • CVE-2009-3585
    24Наблюдать

    Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.

    СредняяCVSS 5,8Эксплойта нетEPSS 3 %

    bestpractical · rt2 дек. 2009 г.

  • CVE-2009-4151
    24Наблюдать

    Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.

    СредняяCVSS 5,8Эксплойта нетEPSS 2 %

    bestpractical · rt2 дек. 2009 г.

  • CVE-2012-4733
    24Наблюдать

    Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows

    СредняяCVSS 6,0Эксплойта нетEPSS 2 %

    bestpractical · rt23 авг. 2013 г.