CVE-2011-5093: Medium severity best practical solutions request tracker vulnerability
Best Practical Solutions RT 4.x before 4.0.6 does not properly implement the DisallowExecuteCode option, which allows remote authenticated users to bypass intended access restrictions and execute arbitrary code by leveraging access to a privileged account, a different vulnerability than CVE-2011-4458 and CVE-2011-5092.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5093?
CVE-2011-5093 is considered a high-severity vulnerability due to its ability to allow remote authenticated users to execute arbitrary code.
How do I fix CVE-2011-5093?
To fix CVE-2011-5093, you should upgrade to Best Practical Solutions RT version 4.0.6 or later.
What software versions are affected by CVE-2011-5093?
CVE-2011-5093 affects Best Practical Solutions RT versions 4.0.0 through 4.0.5, including various release candidates.
Can CVE-2011-5093 be exploited without a privileged account?
No, CVE-2011-5093 requires a remote authenticated user with a privileged account to exploit the vulnerability.
What type of vulnerability is CVE-2011-5093?
CVE-2011-5093 is a code execution vulnerability that allows unauthorized code execution due to improper access restrictions.