bestpractical kayıtları
bestpractical üreticisine ait 73 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %83,6
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')20
- CWE-264 Permissions, Privileges, and Access Controls10
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-255 Credentials Management Errors4
- CWE-352 Cross-Site Request Forgery (CSRF)4
- CWE-310 Cryptographic Issues4
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
73 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2017-5944İstismar yok | The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remobestpractical · request tracker · CWE-20 | Yüksek8,8 | — | %2,8 | 3 Tem 2017 |
36İzleyin | CVE-2022-25801İstismar yok | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.bestpractical · request tracker for incident response · CWE-918 | Kritik9,1 | — | %0,9 | 14 Tem 2022 |
36İzleyin | CVE-2022-25800İstismar yok | Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.bestpractical · request tracker for incident response · CWE-918 | Kritik9,1 | — | %0,9 | 14 Tem 2022 |
36İzleyin | CVE-2026-44231İstismar yok | RT: Privilege escalation and information disclosure via REST 2.0 user collection endpointbestpractical · request tracker · CWE-200 | Kritik9,1 | — | %0,4 | 20 Tem 2026 |
35İzleyin | CVE-2017-5943İstismar yok | Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information bestpractical · request tracker · CWE-352 | Yüksek8,8 | — | %0,8 | 3 Tem 2017 |
31İzleyin | CVE-2011-5092İstismar yok | Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges vbestpractical · rt · CWE-264 | Yüksek7,5 | — | %2,8 | 4 Haz 2012 |
31İzleyin | CVE-2013-3525Kavram kanıtı | SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commanbestpractical · request tracker · CWE-89 | Yüksek7,5 | — | %2,8 | 10 May 2013 |
31İzleyin | CVE-2018-18898İstismar yok | The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algoritbestpractical · request tracker · CWE-400 | Yüksek7,5 | — | %2,4 | 21 Mar 2019 |
31İzleyin | CVE-2021-38562İstismar yok | Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a bestpractical · request tracker · CWE-203 | Yüksek7,5 | — | %1,8 | 18 Eki 2021 |
30İzleyin | CVE-2023-41259İstismar yok | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in bestpractical · request tracker · CWE-200 | Yüksek7,5 | — | %0,7 | 3 Kas 2023 |
30İzleyin | CVE-2023-41260İstismar yok | Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API callbestpractical · request tracker · CWE-200 | Yüksek7,5 | — | %0,7 | 3 Kas 2023 |
30İzleyin | CVE-2023-45024İstismar yok | Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.bestpractical · request tracker · CWE-200 | Yüksek7,5 | — | %0,6 | 3 Kas 2023 |
29İzleyin | CVE-2014-9472İstismar yok | The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a dendebian · debian linux · CWE-399 | Yüksek7,1 | — | %2,8 | 9 Mar 2015 |
28İzleyin | CVE-2011-4458İstismar yok | Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enablbestpractical · rt · CWE-94 | Orta6,8 | — | %3,1 | 4 Haz 2012 |
28İzleyin | CVE-2013-3370İstismar yok | Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allbestpractical · rt · CWE-264 | Orta6,8 | — | %2,3 | 23 Ağu 2013 |
27İzleyin | CVE-2011-5093İstismar yok | Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated ubestpractical · rt · CWE-264 | Orta6,5 | — | %2,1 | 4 Haz 2012 |
27İzleyin | CVE-2011-4460İstismar yok | SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users bestpractical · rt · CWE-89 | Orta6,5 | — | %1,8 | 4 Haz 2012 |
27İzleyin | CVE-2011-2085İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote atbestpractical · rt · CWE-352 | Orta6,8 | — | %1,1 | 4 Haz 2012 |
27İzleyin | CVE-2012-4732İstismar yok | Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other versionbestpractical · rt · CWE-352 | Orta6,8 | — | %0,9 | 11 Kas 2012 |
26İzleyin | CVE-2015-1464İstismar yok | RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.fedoraproject · fedora · CWE-284 | Orta6,4 | — | %2,0 | 9 Mar 2015 |
26İzleyin | CVE-2011-1686İstismar yok | Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rcbestpractical · rt · CWE-89 | Orta6,5 | — | %1,3 | 22 Nis 2011 |
25İzleyin | CVE-2012-6579İstismar yok | Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encryptibestpractical · request tracker · CWE-310 | Orta6,4 | — | %0,8 | 24 Tem 2013 |
24İzleyin | CVE-2009-3585İstismar yok | Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.bestpractical · rt · CWE-287 | Orta5,8 | — | %2,7 | 2 Ara 2009 |
24İzleyin | CVE-2009-4151İstismar yok | Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.bestpractical · rt · CWE-287 | Orta5,8 | — | %1,8 | 2 Ara 2009 |
24İzleyin | CVE-2012-4733İstismar yok | Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allowsbestpractical · rt · CWE-255 | Orta6,0 | — | %1,6 | 23 Ağu 2013 |
- CVE-2017-594436İzleyin
The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remo
YüksekCVSS 8,8İstismar yokEPSS %3bestpractical · request tracker3 Tem 2017
- CVE-2022-2580136İzleyin
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.
KritikCVSS 9,1İstismar yokEPSS %1bestpractical · request tracker for incident response14 Tem 2022
- CVE-2022-2580036İzleyin
Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.
KritikCVSS 9,1İstismar yokEPSS %1bestpractical · request tracker for incident response14 Tem 2022
- CVE-2026-4423136İzleyin
RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint
KritikCVSS 9,1İstismar yokEPSS %0bestpractical · request tracker20 Tem 2026
- CVE-2017-594335İzleyin
Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information
YüksekCVSS 8,8İstismar yokEPSS %1bestpractical · request tracker3 Tem 2017
- CVE-2011-509231İzleyin
Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges v
YüksekCVSS 7,5İstismar yokEPSS %3bestpractical · rt4 Haz 2012
- CVE-2013-352531İzleyin
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL comman
YüksekCVSS 7,5Kavram kanıtıEPSS %3bestpractical · request tracker10 May 2013
- CVE-2018-1889831İzleyin
The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorit
YüksekCVSS 7,5İstismar yokEPSS %2bestpractical · request tracker21 Mar 2019
- CVE-2021-3856231İzleyin
Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a
YüksekCVSS 7,5İstismar yokEPSS %2bestpractical · request tracker18 Eki 2021
- CVE-2023-4125930İzleyin
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in
YüksekCVSS 7,5İstismar yokEPSS %1bestpractical · request tracker3 Kas 2023
- CVE-2023-4126030İzleyin
Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API call
YüksekCVSS 7,5İstismar yokEPSS %1bestpractical · request tracker3 Kas 2023
- CVE-2023-4502430İzleyin
Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.
YüksekCVSS 7,5İstismar yokEPSS %1bestpractical · request tracker3 Kas 2023
- CVE-2014-947229İzleyin
The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a den
YüksekCVSS 7,1İstismar yokEPSS %3debian · debian linux9 Mar 2015
- CVE-2011-445828İzleyin
Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabl
OrtaCVSS 6,8İstismar yokEPSS %3bestpractical · rt4 Haz 2012
- CVE-2013-337028İzleyin
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which all
OrtaCVSS 6,8İstismar yokEPSS %2bestpractical · rt23 Ağu 2013
- CVE-2011-509327İzleyin
Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated u
OrtaCVSS 6,5İstismar yokEPSS %2bestpractical · rt4 Haz 2012
- CVE-2011-446027İzleyin
SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users
OrtaCVSS 6,5İstismar yokEPSS %2bestpractical · rt4 Haz 2012
- CVE-2011-208527İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote at
OrtaCVSS 6,8İstismar yokEPSS %1bestpractical · rt4 Haz 2012
- CVE-2012-473227İzleyin
Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other version
OrtaCVSS 6,8İstismar yokEPSS %1bestpractical · rt11 Kas 2012
- CVE-2015-146426İzleyin
RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.
OrtaCVSS 6,4İstismar yokEPSS %2fedoraproject · fedora9 Mar 2015
- CVE-2011-168626İzleyin
Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc
OrtaCVSS 6,5İstismar yokEPSS %1bestpractical · rt22 Nis 2011
- CVE-2012-657925İzleyin
Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encrypti
OrtaCVSS 6,4İstismar yokEPSS %1bestpractical · request tracker24 Tem 2013
- CVE-2009-358524İzleyin
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.
OrtaCVSS 5,8İstismar yokEPSS %3bestpractical · rt2 Ara 2009
- CVE-2009-415124İzleyin
Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.
OrtaCVSS 5,8İstismar yokEPSS %2bestpractical · rt2 Ara 2009
- CVE-2012-473324İzleyin
Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows
OrtaCVSS 6,0İstismar yokEPSS %2bestpractical · rt23 Ağu 2013