CVE-2011-4460

Bestpractical RT - SQL Injection

Title source: rule
STIX 2.1

Description

SQL injection vulnerability in Best Practical Solutions RT 2.x and 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to execute arbitrary SQL commands by leveraging access to a privileged account.

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/49259
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/82136
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/75824
Patch, Vendor Advisory mailing-list x_refsource_mlist
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/53660

Scores

EPSS 0.0177
EPSS Percentile 75.9%

Details

CWE
CWE-89
Status published
Products (44)
bestpractical/rt 2.0.0
bestpractical/rt 2.0.1
bestpractical/rt 2.0.2
bestpractical/rt 2.0.3
bestpractical/rt 2.0.4
bestpractical/rt 2.0.5
bestpractical/rt 2.0.5.1
bestpractical/rt 2.0.5.3
bestpractical/rt 2.0.6
bestpractical/rt 2.0.7
... and 34 more
Published Jun 04, 2012
Tracked Since Feb 18, 2026