blog.bestpractical.com
http://blog.bestpractical.com/2013/04/on-our-security-policies.html CVE-2013-3525
Request Tracker - 'ShowPending' SQL Injection
Record summary
CVE-2013-3525 has a selected CVSS score of 7.5; EIP currently links 1 catalogued exploit.
Description
SQL injection vulnerability in Approvals/ in Request Tracker (RT) 4.0.10 and earlier allows remote attackers to execute arbitrary SQL commands via the ShowPending parameter. NOTE: the vendor disputes this issue, stating "We were unable to replicate it, and the individual that reported it retracted their report," and "we had verified that the claimed exploit did not function according to the author's claims.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBRequest Tracker - 'ShowPending' SQL InjectionExploitDB exploitby chekiNot analyzed1 file
References
7cxsecurity.com
http://cxsecurity.com/issue/WLB-2013040083 92265vdb entry
http://osvdb.org/92265 packetstormsecurity.com
http://packetstormsecurity.com/files/121245/RT-Request-Tracker-4.0.10-SQL-Injection.html 59022vdb entry
http://www.securityfocus.com/bid/59022 requesttracker-showpending-sql-injection(83375)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/83375 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2013-3525