FAQ manager for Request Tracker (RTFM) before 2.4.5 does not properly check user rights, which allows remote authenticated users to create arbitrary articles in arbitrary classes via unknown vectors.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rtfm | Bestpractical | * | 2.4.3 (including) |
Rtfm | Bestpractical | 2.2.0 (including) | 2.2.0 (including) |
Rtfm | Bestpractical | 2.2.1 (including) | 2.2.1 (including) |
Rtfm | Bestpractical | 2.2.2 (including) | 2.2.2 (including) |
Rtfm | Bestpractical | 2.4.0 (including) | 2.4.0 (including) |
Rtfm | Bestpractical | 2.4.1 (including) | 2.4.1 (including) |
Rtfm | Bestpractical | 2.4.2 (including) | 2.4.2 (including) |
Rtfm | Ubuntu | hardy | * |
Rtfm | Ubuntu | lucid | * |
Rtfm | Ubuntu | oneiric | * |
Rtfm | Ubuntu | precise | * |
Rtfm | Ubuntu | upstream | * |