SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author's claims.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2013-05-10T21:00:00
Updated: 2017-08-28T12:57:01
Reserved: 2013-05-10T00:00:00
Link: CVE-2013-3525
JSON object: View
NVD Information
Status : Modified
Published: 2013-05-10T21:55:02.430
Modified: 2024-05-17T00:55:53.087
Link: CVE-2013-3525
JSON object: View
Redhat Information
No data.
CWE