CVE-2013-3736
05.05.2014, 17:06
Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the name of an attached file.
Vendor | Product | Version |
---|---|---|
bestpractical | request_tracker | 4.0.0 |
bestpractical | request_tracker | 4.0.1 |
bestpractical | request_tracker | 4.0.2 |
bestpractical | request_tracker | 4.0.3 |
bestpractical | request_tracker | 4.0.4 |
bestpractical | request_tracker | 4.0.5 |
bestpractical | request_tracker | 4.0.6 |
bestpractical | request_tracker | 4.0.7 |
bestpractical | request_tracker | 4.0.8 |
bestpractical | request_tracker | 4.0.9 |
bestpractical | request_tracker | 4.0.10 |
bestpractical | request_tracker | 4.0.11 |
bestpractical | request_tracker | 4.0.12 |
bestpractical | rt-extension-mobileui | 𝑥 ≤ 1.02 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References