CVE Vulnerabilities

CVE-2011-1008

Published: Feb 28, 2011 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Scrips_Overlay.pm in Best Practical Solutions RT before 3.8.9 does not properly restrict access to a TicketObj in a Scrip after a CurrentUser change, which allows remote authenticated users to obtain sensitive information via unspecified vectors, as demonstrated by custom-field value information, related to SQL logging.

Affected Software

NameVendorStart VersionEnd Version
RtBestpractical*3.8.9 (including)
RtBestpractical1.0.0 (including)1.0.0 (including)
RtBestpractical1.0.1 (including)1.0.1 (including)
RtBestpractical1.0.2 (including)1.0.2 (including)
RtBestpractical1.0.3 (including)1.0.3 (including)
RtBestpractical1.0.4 (including)1.0.4 (including)
RtBestpractical1.0.5 (including)1.0.5 (including)
RtBestpractical1.0.6 (including)1.0.6 (including)
RtBestpractical1.0.7 (including)1.0.7 (including)
RtBestpractical2.0.0 (including)2.0.0 (including)
RtBestpractical2.0.1 (including)2.0.1 (including)
RtBestpractical2.0.2 (including)2.0.2 (including)
RtBestpractical2.0.3 (including)2.0.3 (including)
RtBestpractical2.0.4 (including)2.0.4 (including)
RtBestpractical2.0.5 (including)2.0.5 (including)
RtBestpractical2.0.5.1 (including)2.0.5.1 (including)
RtBestpractical2.0.5.3 (including)2.0.5.3 (including)
RtBestpractical2.0.6 (including)2.0.6 (including)
RtBestpractical2.0.7 (including)2.0.7 (including)
RtBestpractical2.0.8 (including)2.0.8 (including)
RtBestpractical2.0.8.2 (including)2.0.8.2 (including)
RtBestpractical2.0.9 (including)2.0.9 (including)
RtBestpractical2.0.11 (including)2.0.11 (including)
RtBestpractical2.0.12 (including)2.0.12 (including)
RtBestpractical2.0.13 (including)2.0.13 (including)
RtBestpractical2.0.14 (including)2.0.14 (including)
RtBestpractical2.0.15 (including)2.0.15 (including)
RtBestpractical3.0.0 (including)3.0.0 (including)
RtBestpractical3.0.1 (including)3.0.1 (including)
RtBestpractical3.0.2 (including)3.0.2 (including)
RtBestpractical3.0.3 (including)3.0.3 (including)
RtBestpractical3.0.4 (including)3.0.4 (including)
RtBestpractical3.0.5 (including)3.0.5 (including)
RtBestpractical3.0.6 (including)3.0.6 (including)
RtBestpractical3.0.7 (including)3.0.7 (including)
RtBestpractical3.0.7.1 (including)3.0.7.1 (including)
RtBestpractical3.0.8 (including)3.0.8 (including)
RtBestpractical3.0.9 (including)3.0.9 (including)
RtBestpractical3.0.10 (including)3.0.10 (including)
RtBestpractical3.0.11 (including)3.0.11 (including)
RtBestpractical3.0.12 (including)3.0.12 (including)
RtBestpractical3.2.0 (including)3.2.0 (including)
RtBestpractical3.2.1 (including)3.2.1 (including)
RtBestpractical3.2.2 (including)3.2.2 (including)
RtBestpractical3.2.3 (including)3.2.3 (including)
RtBestpractical3.4.0 (including)3.4.0 (including)
RtBestpractical3.4.1 (including)3.4.1 (including)
RtBestpractical3.4.2 (including)3.4.2 (including)
RtBestpractical3.4.3 (including)3.4.3 (including)
RtBestpractical3.4.4 (including)3.4.4 (including)
RtBestpractical3.4.5 (including)3.4.5 (including)
RtBestpractical3.4.6 (including)3.4.6 (including)
RtBestpractical3.6.0 (including)3.6.0 (including)
RtBestpractical3.6.1 (including)3.6.1 (including)
RtBestpractical3.6.2 (including)3.6.2 (including)
RtBestpractical3.6.3 (including)3.6.3 (including)
RtBestpractical3.6.4 (including)3.6.4 (including)
RtBestpractical3.6.5 (including)3.6.5 (including)
RtBestpractical3.6.6 (including)3.6.6 (including)
RtBestpractical3.6.7 (including)3.6.7 (including)
RtBestpractical3.6.8 (including)3.6.8 (including)
RtBestpractical3.6.9 (including)3.6.9 (including)
RtBestpractical3.8.0 (including)3.8.0 (including)
RtBestpractical3.8.1 (including)3.8.1 (including)
RtBestpractical3.8.2 (including)3.8.2 (including)
RtBestpractical3.8.3 (including)3.8.3 (including)
RtBestpractical3.8.4 (including)3.8.4 (including)
RtBestpractical3.8.5 (including)3.8.5 (including)
RtBestpractical3.8.6 (including)3.8.6 (including)
RtBestpractical3.8.6-rc1 (including)3.8.6-rc1 (including)
RtBestpractical3.8.7-rc1 (including)3.8.7-rc1 (including)
RtBestpractical3.8.8-rc2 (including)3.8.8-rc2 (including)
RtBestpractical3.8.8-rc3 (including)3.8.8-rc3 (including)
RtBestpractical3.8.8-rc4 (including)3.8.8-rc4 (including)
RtBestpractical3.8.9-rc1 (including)3.8.9-rc1 (including)
RtBestpractical3.8.9-rc2 (including)3.8.9-rc2 (including)
Request-tracker3.6Ubuntuhardy*
Request-tracker3.6Ubuntukarmic*
Request-tracker3.8Ubuntukarmic*
Request-tracker3.8Ubuntulucid*
Request-tracker3.8Ubuntumaverick*
Request-tracker3.8Ubuntunatty*
Request-tracker3.8Ubuntuupstream*

References