RT Versions Prior to 3.6.11/3.8.10 Multiple Remote Vulnerabilities
BID:47383
Info
RT Versions Prior to 3.6.11/3.8.10 Multiple Remote Vulnerabilities
| Bugtraq ID: | 47383 |
| Class: | Input Validation Error |
| CVE: |
CVE-2011-1685 CVE-2011-1686 CVE-2011-1687 CVE-2011-1688 CVE-2011-1689 CVE-2011-1690 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 15 2011 12:00AM |
| Updated: | Mar 19 2015 09:11AM |
| Credit: | Reported by the vendor |
| Vulnerable: |
Debian Linux 5.0 sparc Debian Linux 5.0 s/390 Debian Linux 5.0 powerpc Debian Linux 5.0 mipsel Debian Linux 5.0 mips Debian Linux 5.0 m68k Debian Linux 5.0 ia-64 Debian Linux 5.0 ia-32 Debian Linux 5.0 hppa Debian Linux 5.0 armel Debian Linux 5.0 arm Debian Linux 5.0 amd64 Debian Linux 5.0 alpha Debian Linux 5.0 Best Practical Solutions RT 3.8.8 Best Practical Solutions RT 3.8.6 Best Practical Solutions RT 3.8.5 Best Practical Solutions RT 3.8.4 Best Practical Solutions RT 3.8.2 Best Practical Solutions RT 3.6.9 Best Practical Solutions RT 3.6.8 Best Practical Solutions RT 3.6.7 Best Practical Solutions RT 3.6.6 Best Practical Solutions RT 3.6.2 Best Practical Solutions RT 3.8.9 |
| Not Vulnerable: |
Best Practical Solutions RT 3.8.10 Best Practical Solutions RT 3.6.11 |
Discussion
RT Versions Prior to 3.6.11/3.8.10 Multiple Remote Vulnerabilities
RT is prone to multiple remote vulnerabilities, including:
1. A remote code-execution vulnerability
2. Multiple SQL-injection vulnerabilities
3. An information-disclosure vulnerability
4. A security vulnerability that may allow attackers to send authentication data to third party users
5. A directory-traversal vulnerability
6. A cross-site scripting vulnerability
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary script and PHP code and gain access to sensitive information.
RT versions prior to 3.6.11 and 3.8.10 are vulnerable.
RT is prone to multiple remote vulnerabilities, including:
1. A remote code-execution vulnerability
2. Multiple SQL-injection vulnerabilities
3. An information-disclosure vulnerability
4. A security vulnerability that may allow attackers to send authentication data to third party users
5. A directory-traversal vulnerability
6. A cross-site scripting vulnerability
Exploiting these issues could allow an attacker to steal cookie-based authentication credentials, compromise the application, access or modify data, exploit latent vulnerabilities in the underlying database, or execute arbitrary script and PHP code and gain access to sensitive information.
RT versions prior to 3.6.11 and 3.8.10 are vulnerable.
Exploit / POC
RT Versions Prior to 3.6.11/3.8.10 Multiple Remote Vulnerabilities
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
An attacker can exploit these issues via a browser. To exploit a cross-site scripting issue, the attacker must entice an unsuspecting victim to follow a malicious URI.
Solution / Fix
RT Versions Prior to 3.6.11/3.8.10 Multiple Remote Vulnerabilities
Solution:
Updates are available. Please see the references for more information.
Solution:
Updates are available. Please see the references for more information.
References
RT Versions Prior to 3.6.11/3.8.10 Multiple Remote Vulnerabilities
References:
References:
- [Rt-announce] RT 3.6.11 Released - Security Release (Best Practical Solutions)
- [Rt-announce] RT 3.8.10 Released - Security Release (Best Practical Solutions)
- [Rt-announce] Security vulnerabilities in RT (Best Practical Solutions)