İçeriğe atla
Noroxi

bestpractical kayıtları

bestpractical üreticisine ait 73 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
7
Düzeltme kaydı olan
%83,6
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

73 kayıt
  • CVE-2017-5944
    36İzleyin

    The dashboard subscription interface in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 might allow remo

    YüksekCVSS 8,8İstismar yokEPSS %3

    bestpractical · request tracker3 Tem 2017

  • CVE-2022-25801
    36İzleyin

    Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via Scripted Action tools.

    KritikCVSS 9,1İstismar yokEPSS %1

    bestpractical · request tracker for incident response14 Tem 2022

  • CVE-2022-25800
    36İzleyin

    Best Practical RT for Incident Response (RTIR) before 4.0.3 and 5.x before 5.0.3 allows SSRF via the whois lookup tool.

    KritikCVSS 9,1İstismar yokEPSS %1

    bestpractical · request tracker for incident response14 Tem 2022

  • CVE-2026-44231
    36İzleyin

    RT: Privilege escalation and information disclosure via REST 2.0 user collection endpoint

    KritikCVSS 9,1İstismar yokEPSS %0

    bestpractical · request tracker20 Tem 2026

  • CVE-2017-5943
    35İzleyin

    Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2 allows remote attackers to obtain sensitive information

    YüksekCVSS 8,8İstismar yokEPSS %1

    bestpractical · request tracker3 Tem 2017

  • CVE-2011-5092
    31İzleyin

    Best Practical Solutions RT 3.8.x before 3.8.12 and 4.x before 4.0.6 allows remote attackers to execute arbitrary code and gain privileges v

    YüksekCVSS 7,5İstismar yokEPSS %3

    bestpractical · rt4 Haz 2012

  • CVE-2013-3525
    31İzleyin

    SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL comman

    YüksekCVSS 7,5Kavram kanıtıEPSS %3

    bestpractical · request tracker10 May 2013

  • CVE-2018-18898
    31İzleyin

    The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorit

    YüksekCVSS 7,5İstismar yokEPSS %2

    bestpractical · request tracker21 Mar 2019

  • CVE-2021-38562
    31İzleyin

    Best Practical Request Tracker (RT) 4.2 before 4.2.17, 4.4 before 4.4.5, and 5.0 before 5.0.2 allows sensitive information disclosure via a

    YüksekCVSS 7,5İstismar yokEPSS %2

    bestpractical · request tracker18 Eki 2021

  • CVE-2023-41259
    30İzleyin

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Disclosure via fake or spoofed RT email headers in

    YüksekCVSS 7,5İstismar yokEPSS %1

    bestpractical · request tracker3 Kas 2023

  • CVE-2023-41260
    30İzleyin

    Best Practical Request Tracker (RT) before 4.4.7 and 5.x before 5.0.5 allows Information Exposure in responses to mail-gateway REST API call

    YüksekCVSS 7,5İstismar yokEPSS %1

    bestpractical · request tracker3 Kas 2023

  • CVE-2023-45024
    30İzleyin

    Best Practical Request Tracker (RT) 5 before 5.0.5 allows Information Disclosure via a transaction search in the transaction query builder.

    YüksekCVSS 7,5İstismar yokEPSS %1

    bestpractical · request tracker3 Kas 2023

  • CVE-2014-9472
    29İzleyin

    The email gateway in RT (aka Request Tracker) 3.0.0 through 4.x before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to cause a den

    YüksekCVSS 7,1İstismar yokEPSS %3

    debian · debian linux9 Mar 2015

  • CVE-2011-4458
    28İzleyin

    Best Practical Solutions RT 3.6.x, 3.7.x, and 3.8.x before 3.8.12 and 4.x before 4.0.6, when the VERPPrefix and VERPDomain options are enabl

    OrtaCVSS 6,8İstismar yokEPSS %3

    bestpractical · rt4 Haz 2012

  • CVE-2013-3370
    28İzleyin

    Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which all

    OrtaCVSS 6,8İstismar yokEPSS %2

    bestpractical · rt23 Ağu 2013

  • CVE-2011-5093
    27İzleyin

    Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated u

    OrtaCVSS 6,5İstismar yokEPSS %2

    bestpractical · rt4 Haz 2012

  • CVE-2011-4460
    27İzleyin

    SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users

    OrtaCVSS 6,5İstismar yokEPSS %2

    bestpractical · rt4 Haz 2012

  • CVE-2011-2085
    27İzleyin

    Multiple cross-site request forgery (CSRF) vulnerabilities in Best Practical Solutions RT before 3.8.12 and 4.x before 4.0.6 allow remote at

    OrtaCVSS 6,8İstismar yokEPSS %1

    bestpractical · rt4 Haz 2012

  • CVE-2012-4732
    27İzleyin

    Cross-site request forgery (CSRF) vulnerability in Request Tracker (RT) 3.8.12 and other versions before 3.8.15, and 4.0.6 and other version

    OrtaCVSS 6,8İstismar yokEPSS %1

    bestpractical · rt11 Kas 2012

  • CVE-2015-1464
    26İzleyin

    RT (aka Request Tracker) before 4.0.23 and 4.2.x before 4.2.10 allows remote attackers to hijack sessions via an RSS feed URL.

    OrtaCVSS 6,4İstismar yokEPSS %2

    fedoraproject · fedora9 Mar 2015

  • CVE-2011-1686
    26İzleyin

    Multiple SQL injection vulnerabilities in Best Practical Solutions RT 2.0.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc

    OrtaCVSS 6,5İstismar yokEPSS %1

    bestpractical · rt22 Nis 2011

  • CVE-2012-6579
    25İzleyin

    Best Practical Solutions RT 3.8.x before 3.8.15 and 4.0.x before 4.0.8, when GnuPG is enabled, allows remote attackers to configure encrypti

    OrtaCVSS 6,4İstismar yokEPSS %1

    bestpractical · request tracker24 Tem 2013

  • CVE-2009-3585
    24İzleyin

    Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.

    OrtaCVSS 5,8İstismar yokEPSS %3

    bestpractical · rt2 Ara 2009

  • CVE-2009-4151
    24İzleyin

    Session fixation vulnerability in html/Elements/SetupSessionCookie in Best Practical Solutions RT 3.0.0 through 3.6.9 and 3.8.x through 3.8.

    OrtaCVSS 5,8İstismar yokEPSS %2

    bestpractical · rt2 Ara 2009

  • CVE-2012-4733
    24İzleyin

    Request Tracker (RT) 4.x before 4.0.13 does not properly enforce the DeleteTicket and "custom lifecycle transition" permission, which allows

    OrtaCVSS 6,0İstismar yokEPSS %2

    bestpractical · rt23 Ağu 2013