CVE-2011-1007

Severity

21%

Complexity

39%

Confidentiality

48%

Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login, which allows physically proximate attackers to obtain credentials by resubmitting the login form via the back button of a web browser on an unattended workstation after an RT logout.

Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login, which allows physically proximate attackers to obtain credentials by resubmitting the login form via the back button of a web browser on an unattended workstation after an RT logout.

CVSS 2.0 Base Score 2.1. CVSS Attack Vector: local. CVSS Attack Complexity: low. CVSS Vector: (AV:L/AC:L/Au:N/C:P/I:N/A:N).

Overview

Type

Best Practical Solutions RT

First reported 14 years ago

2011-02-28 16:00:00

Last updated 7 years ago

2017-08-17 01:33:00

Affected Software

Best Practical Solutions RT 1.0.0

1.0.0

Best Practical Solutions RT 1.0.1

1.0.1

Best Practical Solutions RT 1.0.2

1.0.2

Best Practical Solutions RT 1.0.3

1.0.3

Best Practical Solutions RT 1.0.4

1.0.4

Best Practical Solutions RT 1.0.5

1.0.5

Best Practical Solutions RT 1.0.6

1.0.6

Best Practical Solutions RT 1.0.7

1.0.7

Best Practical Solutions RT 2.0.0

2.0.0

Best Practical Solutions RT 2.0.1

2.0.1

Best Practical Solutions RT 2.0.2

2.0.2

Best Practical Solutions RT 2.0.3

2.0.3

Best Practical Solutions RT 2.0.4

2.0.4

Best Practical Solutions RT 2.0.5

2.0.5

Best Practical Solutions RT 2.0.5.1

2.0.5.1

Best Practical Solutions RT 2.0.5.3

2.0.5.3

Best Practical Solutions RT 2.0.6

2.0.6

Best Practical Solutions RT 2.0.7

2.0.7

Best Practical Solutions RT 2.0.8

2.0.8

Best Practical Solutions RT 2.0.8.2

2.0.8.2

Best Practical Solutions RT 2.0.9

2.0.9

Best Practical Solutions RT 2.0.11

2.0.11

Best Practical Solutions RT 2.0.12

2.0.12

Best Practical Solutions RT 2.0.13

2.0.13

Best Practical Solutions RT 2.0.14

2.0.14

Best Practical Solutions RT 2.0.15

2.0.15

Best Practical Solutions RT 3.0.0

3.0.0

Best Practical Solutions RT 3.0.1

3.0.1

Best Practical Solutions RT 3.0.2

3.0.2

Best Practical Solutions RT 3.0.3

3.0.3

Best Practical Solutions RT 3.0.4

3.0.4

Best Practical Solutions RT 3.0.5

3.0.5

Best Practical Solutions RT 3.0.6

3.0.6

Best Practical Solutions RT 3.0.7

3.0.7

Best Practical Solutions RT 3.0.7.1

3.0.7.1

Best Practical Solutions RT 3.0.8

3.0.8

Best Practical Solutions RT 3.0.9

3.0.9

Best Practical Solutions RT 3.0.10

3.0.10

Best Practical Solutions RT 3.0.11

3.0.11

Best Practical Solutions RT 3.0.12

3.0.12

Best Practical Solutions RT 3.2.0

3.2.0

Best Practical Solutions RT 3.2.1

3.2.1

Best Practical Solutions RT 3.2.2

3.2.2

Best Practical Solutions RT 3.2.3

3.2.3

Best Practical Solutions RT 3.4.0

3.4.0

Best Practical Solutions RT 3.4.1

3.4.1

Best Practical Solutions RT 3.4.2

3.4.2

Best Practical Solutions RT 3.4.3

3.4.3

Best Practical Solutions RT 3.4.4

3.4.4

Best Practical Solutions RT 3.4.5

3.4.5

Best Practical Solutions RT 3.4.6

3.4.6

Best Practical Solutions RT 3.6.0

3.6.0

Best Practical Solutions RT 3.6.1

3.6.1

Best Practical Solutions RT 3.6.2

3.6.2

Best Practical Solutions RT 3.6.3

3.6.3

Best Practical Solutions RT 3.6.4

3.6.4

Best Practical Solutions RT 3.6.5

3.6.5

Best Practical Solutions RT 3.6.6

3.6.6

Best Practical Solutions RT 3.6.7

3.6.7

Best Practical Solutions RT 3.6.8

3.6.8

Best Practical Solutions RT 3.6.9

3.6.9

Best Practical Solutions RT 3.8.0

3.8.0

Best Practical Solutions RT 3.8.1

3.8.1

Best Practical Solutions RT 3.8.2

3.8.2

Best Practical Solutions RT 3.8.3

3.8.3

Best Practical Solutions RT 3.8.4

3.8.4

Best Practical Solutions RT 3.8.5

3.8.5

Best Practical Solutions RT 3.8.6

3.8.6

Best Practical Solutions RT 3.8.6 Release Candidate 1

3.8.6

Best Practical Solutions RT 3.8.7 Release Candidate 1

3.8.7

Best Practical Solutions RT 3.8.8 Release Candidate 2

3.8.8

Best Practical Solutions RT 3.8.8 Release Candidate 3

3.8.8

Best Practical Solutions RT 3.8.8 Release Candidate 4

3.8.8

Best Practical Solutions RT 3.8.9 Release Candidate 1

3.8.9

Best Practical Solutions RT 3.8.9 Release Candidate 2

3.8.9

References

http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=614575

Patch

http://issues.bestpractical.com/Ticket/Display.html?id=15804

[rt-announce] 20110216 RT 3.8.9 Released

Patch

[oss-security] 20110222 Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition

Patch

[oss-security] 20110222 Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition

Patch

[oss-security] 20110222 CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition

Patch

[oss-security] 20110223 Re: Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition

[oss-security] 20110224 Re: Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition

[oss-security] 20110224 Re: Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition

[oss-security] 20110224 Re: Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition

71012

43438

Vendor Advisory

ADV-2011-0475

Vendor Advisory

rt-login-information-disclosure(65771)

https://github.com/bestpractical/rt/commit/057552287159e801535e59b8fbd5bd98d1322069

Patch

https://github.com/bestpractical/rt/commit/917c211820590950f7eb0521f7f43b31aeed44c4

Patch

Stay updated

ExploitPedia is constantly evolving. Sign up to receive a notification when we release additional functionality.

Get in touch

If you'd like to report a bug or have any suggestions for improvements then please do get in touch with us using this form. We will get back to you as soon as we can.