Записи bestpractical
73 опубликованных записей вендора bestpractical.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 7
- С записью об исправлении
- 83,6 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-255 Credentials Management Errors4
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-310 Cryptographic Issues4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
73 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2017-5944Эксплойта нет | The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remobestpractical · request tracker · CWE-20 | Высокая8,8 | — | 2,8 % | 3 июл. 2017 г. |
36Наблюдать | CVE-2022-25801Эксплойта нет | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.bestpractical · request tracker for incident response · CWE-918 | Критическая9,1 | — | 0,9 % | 14 июл. 2022 г. |
36Наблюдать | CVE-2022-25800Эксплойта нет | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.bestpractical · request tracker for incident response · CWE-918 | Критическая9,1 | — | 0,9 % | 14 июл. 2022 г. |
36Наблюдать | CVE-2026-44231Эксплойта нет | RT: Privilege escalation and information disclosure via REST 2.0 user collection endpointbestpractical · request tracker · CWE-200 | Критическая9,1 | — | 0,4 % | 20 июл. 2026 г. |
35Наблюдать | CVE-2017-5943Эксплойта нет | Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information bestpractical · request tracker · CWE-352 | Высокая8,8 | — | 0,8 % | 3 июл. 2017 г. |
31Наблюдать | CVE-2011-5092Эксплойта нет | Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges vbestpractical · rt · CWE-264 | Высокая7,5 | — | 2,8 % | 4 июн. 2012 г. |
31Наблюдать | CVE-2013-3525Proof of concept | SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commanbestpractical · request tracker · CWE-89 | Высокая7,5 | — | 2,8 % | 10 мая 2013 г. |
31Наблюдать | CVE-2018-18898Эксплойта нет | The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algoritbestpractical · request tracker · CWE-400 | Высокая7,5 | — | 2,4 % | 21 мар. 2019 г. |
31Наблюдать | CVE-2021-38562Эксплойта нет | Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a bestpractical · request tracker · CWE-203 | Высокая7,5 | — | 1,8 % | 18 окт. 2021 г. |
30Наблюдать | CVE-2023-41259Эксплойта нет | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in bestpractical · request tracker · CWE-200 | Высокая7,5 | — | 0,7 % | 3 нояб. 2023 г. |
30Наблюдать | CVE-2023-41260Эксплойта нет | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API callbestpractical · request tracker · CWE-200 | Высокая7,5 | — | 0,7 % | 3 нояб. 2023 г. |
30Наблюдать | CVE-2023-45024Эксплойта нет | Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.bestpractical · request tracker · CWE-200 | Высокая7,5 | — | 0,6 % | 3 нояб. 2023 г. |
29Наблюдать | CVE-2014-9472Эксплойта нет | The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a dendebian · debian linux · CWE-399 | Высокая7,1 | — | 2,8 % | 9 мар. 2015 г. |
28Наблюдать | CVE-2011-4458Эксплойта нет | Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enablbestpractical · rt · CWE-94 | Средняя6,8 | — | 3,1 % | 4 июн. 2012 г. |
28Наблюдать | CVE-2013-3370Эксплойта нет | Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allbestpractical · rt · CWE-264 | Средняя6,8 | — | 2,3 % | 23 авг. 2013 г. |
27Наблюдать | CVE-2011-5093Эксплойта нет | Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated ubestpractical · rt · CWE-264 | Средняя6,5 | — | 2,1 % | 4 июн. 2012 г. |
27Наблюдать | CVE-2011-4460Эксплойта нет | SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users bestpractical · rt · CWE-89 | Средняя6,5 | — | 1,8 % | 4 июн. 2012 г. |
27Наблюдать | CVE-2011-2085Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote atbestpractical · rt · CWE-352 | Средняя6,8 | — | 1,1 % | 4 июн. 2012 г. |
27Наблюдать | CVE-2012-4732Эксплойта нет | Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versionbestpractical · rt · CWE-352 | Средняя6,8 | — | 0,9 % | 11 нояб. 2012 г. |
26Наблюдать | CVE-2015-1464Эксплойта нет | RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.fedoraproject · fedora · CWE-284 | Средняя6,4 | — | 2,0 % | 9 мар. 2015 г. |
26Наблюдать | CVE-2011-1686Эксплойта нет | Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rcbestpractical · rt · CWE-89 | Средняя6,5 | — | 1,3 % | 22 апр. 2011 г. |
25Наблюдать | CVE-2012-6579Эксплойта нет | Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryptibestpractical · request tracker · CWE-310 | Средняя6,4 | — | 0,8 % | 24 июл. 2013 г. |
24Наблюдать | CVE-2009-3585Эксплойта нет | Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.bestpractical · rt · CWE-287 | Средняя5,8 | — | 2,7 % | 2 дек. 2009 г. |
24Наблюдать | CVE-2009-4151Эксплойта нет | Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.bestpractical · rt · CWE-287 | Средняя5,8 | — | 1,8 % | 2 дек. 2009 г. |
24Наблюдать | CVE-2012-4733Эксплойта нет | Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allowsbestpractical · rt · CWE-255 | Средняя6,0 | — | 1,6 % | 23 авг. 2013 г. |
- CVE-2017-594436Наблюдать
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remo
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %bestpractical · request tracker3 июл. 2017 г.
- CVE-2022-2580136Наблюдать
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %bestpractical · request tracker for incident response14 июл. 2022 г.
- CVE-2022-2580036Наблюдать
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %bestpractical · request tracker for incident response14 июл. 2022 г.
- CVE-2026-4423136Наблюдать
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %bestpractical · request tracker20 июл. 2026 г.
- CVE-2017-594335Наблюдать
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %bestpractical · request tracker3 июл. 2017 г.
- CVE-2011-509231Наблюдать
Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges v
ВысокаяCVSS 7,5Эксплойта нетEPSS 3 %bestpractical · rt4 июн. 2012 г.
- CVE-2013-352531Наблюдать
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL comman
ВысокаяCVSS 7,5Proof of conceptEPSS 3 %bestpractical · request tracker10 мая 2013 г.
- CVE-2018-1889831Наблюдать
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorit
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bestpractical · request tracker21 мар. 2019 г.
- CVE-2021-3856231Наблюдать
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %bestpractical · request tracker18 окт. 2021 г.
- CVE-2023-4125930Наблюдать
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bestpractical · request tracker3 нояб. 2023 г.
- CVE-2023-4126030Наблюдать
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API call
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bestpractical · request tracker3 нояб. 2023 г.
- CVE-2023-4502430Наблюдать
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %bestpractical · request tracker3 нояб. 2023 г.
- CVE-2014-947229Наблюдать
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a den
ВысокаяCVSS 7,1Эксплойта нетEPSS 3 %debian · debian linux9 мар. 2015 г.
- CVE-2011-445828Наблюдать
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabl
СредняяCVSS 6,8Эксплойта нетEPSS 3 %bestpractical · rt4 июн. 2012 г.
- CVE-2013-337028Наблюдать
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which all
СредняяCVSS 6,8Эксплойта нетEPSS 2 %bestpractical · rt23 авг. 2013 г.
- CVE-2011-509327Наблюдать
Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated u
СредняяCVSS 6,5Эксплойта нетEPSS 2 %bestpractical · rt4 июн. 2012 г.
- CVE-2011-446027Наблюдать
SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users
СредняяCVSS 6,5Эксплойта нетEPSS 2 %bestpractical · rt4 июн. 2012 г.
- CVE-2011-208527Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote at
СредняяCVSS 6,8Эксплойта нетEPSS 1 %bestpractical · rt4 июн. 2012 г.
- CVE-2012-473227Наблюдать
Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other version
СредняяCVSS 6,8Эксплойта нетEPSS 1 %bestpractical · rt11 нояб. 2012 г.
- CVE-2015-146426Наблюдать
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.
СредняяCVSS 6,4Эксплойта нетEPSS 2 %fedoraproject · fedora9 мар. 2015 г.
- CVE-2011-168626Наблюдать
Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc
СредняяCVSS 6,5Эксплойта нетEPSS 1 %bestpractical · rt22 апр. 2011 г.
- CVE-2012-657925Наблюдать
Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encrypti
СредняяCVSS 6,4Эксплойта нетEPSS 1 %bestpractical · request tracker24 июл. 2013 г.
- CVE-2009-358524Наблюдать
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.
СредняяCVSS 5,8Эксплойта нетEPSS 3 %bestpractical · rt2 дек. 2009 г.
- CVE-2009-415124Наблюдать
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.
СредняяCVSS 5,8Эксплойта нетEPSS 2 %bestpractical · rt2 дек. 2009 г.
- CVE-2012-473324Наблюдать
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows
СредняяCVSS 6,0Эксплойта нетEPSS 2 %bestpractical · rt23 авг. 2013 г.