CVE-2011-1688: Path Traversal
Directory traversal vulnerability in Best Practical Solutions RT 3.2.0 through 3.6.10, 3.8.0 through 3.8.9, and 4.0.0rc through 4.0.0rc7 allows remote attackers to read arbitrary files via a crafted HTTP request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2011-1688?
CVE-2011-1688 has a severity rating that indicates it allows remote attackers to exploit a directory traversal vulnerability.
How do I fix CVE-2011-1688?
To fix CVE-2011-1688, you should upgrade to a version of Best Practical Solutions RT that is not affected by this vulnerability.
What versions of RT are affected by CVE-2011-1688?
CVE-2011-1688 affects Best Practical Solutions RT versions from 3.2.0 through 3.6.10 and 3.8.0 through 3.8.9 as well as certain release candidates of version 4.0.0.
What type of attacks does CVE-2011-1688 enable?
CVE-2011-1688 enables directory traversal attacks, allowing attackers to read arbitrary files on the server.
Is there a workaround for CVE-2011-1688 if I cannot upgrade RT?
While an official workaround is not provided, restricting external access to the affected RT instances may mitigate some risks associated with CVE-2011-1688.