CVE-2013-3372
published 2013-08-23CVE-2013-3372: Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly…
PriorityP417medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EPSS
2.06%
78.9th percentile
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site scripting (XSS) attacks via unspecified vectors.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
| bestpractical | rt | — | — |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g7wx-g2c5-qxjv: Request Tracker (RT) 3
ghsa_unreviewed·2022-05-17
CVE-2013-3372 [MEDIUM] CWE-79 GHSA-g7wx-g2c5-qxjv: Request Tracker (RT) 3
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site scripting (XSS) attacks via unspecified vectors.
OSV
CVE-2013-3372: Request Tracker (RT) 3
osv·2013-08-23·CVSS 4.3
CVE-2013-3372 [MEDIUM] CVE-2013-3372: Request Tracker (RT) 3
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site scripting (XSS) attacks via unspecified vectors.
Debian
CVE-2013-3372: request-tracker4 - Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote a...
vendor_debian·2013·CVSS 4.3
CVE-2013-3372 [MEDIUM] CVE-2013-3372: request-tracker4 - Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote a...
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site scripting (XSS) attacks via unspecified vectors.
Scope: local
bookworm: resolved (fixed in 4.0.12-2)
bullseye: resolved (fixed in 4.0.12-2)
sid: resolved (fixed in 4.0.12-2)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2013-May/000228.htmlhttp://secunia.com/advisories/53505http://secunia.com/advisories/53522http://www.debian.org/security/2012/dsa-2670http://www.osvdb.org/93607http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000226.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2013-May/000227.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2013-May/000228.htmlhttp://secunia.com/advisories/53505http://secunia.com/advisories/53522http://www.debian.org/security/2012/dsa-2670http://www.osvdb.org/93607
2013-08-23
Published