CVE-2016-6127
03.07.2017, 16:29
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 4.x before 4.0.25, 4.2.x before 4.2.14, and 4.4.x before 4.4.2, when the AlwaysDownloadAttachments config setting is not in use, allows remote attackers to inject arbitrary web script or HTML via a file upload with an unspecified content type.
Vendor | Product | Version |
---|---|---|
bestpractical | request_tracker | 4.0.0 |
bestpractical | request_tracker | 4.0.1 |
bestpractical | request_tracker | 4.0.2 |
bestpractical | request_tracker | 4.0.3 |
bestpractical | request_tracker | 4.0.4 |
bestpractical | request_tracker | 4.0.5 |
bestpractical | request_tracker | 4.0.6 |
bestpractical | request_tracker | 4.0.7 |
bestpractical | request_tracker | 4.0.8 |
bestpractical | request_tracker | 4.0.9 |
bestpractical | request_tracker | 4.0.10 |
bestpractical | request_tracker | 4.0.11 |
bestpractical | request_tracker | 4.0.12 |
bestpractical | request_tracker | 4.0.13 |
bestpractical | request_tracker | 4.0.14 |
bestpractical | request_tracker | 4.0.15 |
bestpractical | request_tracker | 4.0.16 |
bestpractical | request_tracker | 4.0.17 |
bestpractical | request_tracker | 4.0.18 |
bestpractical | request_tracker | 4.0.19 |
bestpractical | request_tracker | 4.0.20 |
bestpractical | request_tracker | 4.0.21 |
bestpractical | request_tracker | 4.0.22 |
bestpractical | request_tracker | 4.0.23 |
bestpractical | request_tracker | 4.0.24 |
bestpractical | request_tracker | 4.2.0 |
bestpractical | request_tracker | 4.2.1 |
bestpractical | request_tracker | 4.2.2 |
bestpractical | request_tracker | 4.2.3 |
bestpractical | request_tracker | 4.2.4 |
bestpractical | request_tracker | 4.2.5 |
bestpractical | request_tracker | 4.2.6 |
bestpractical | request_tracker | 4.2.7 |
bestpractical | request_tracker | 4.2.8 |
bestpractical | request_tracker | 4.2.9 |
bestpractical | request_tracker | 4.2.10 |
bestpractical | request_tracker | 4.2.11 |
bestpractical | request_tracker | 4.2.12 |
bestpractical | request_tracker | 4.2.13 |
bestpractical | request_tracker | 4.4.0 |
bestpractical | request_tracker | 4.4.1 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
request-tracker4 |
|
References