CVE-2011-2084
CVE-2011-2084
Best Practical Solutions RT 3.x before 3.8.12 and 4.x before 4.0.6 allows remote authenticated users to read (1) hashes of former passwords and (2) ticket correspondence history by leveraging access to a privileged account.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →References
http://lists.bestpractical.com/pipermail/rt-announce/2012-May/000202.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000203.htmlhttp://lists.bestpractical.com/pipermail/rt-announce/2012-May/000204.htmlhttp://secunia.com/advisories/49259http://www.securityfocus.com/bid/53660