CVE-2013-3371: XSS
Published Aug 23, 2013
·Updated
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 3.8.3 through 3.8.16 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the filename of an attachment.
Affected Software
77 affected components
bestpractical RT=3.8.0
bestpractical RT=3.8.0-preflight1
bestpractical RT=3.8.0-rc1
bestpractical RT=3.8.0-rc2
bestpractical RT=3.8.0-rc3
bestpractical RT=3.8.1
bestpractical RT=3.8.1-preflight0
bestpractical RT=3.8.1-rc1
bestpractical RT=3.8.1-rc2
bestpractical RT=3.8.1-rc3
bestpractical RT=3.8.1-rc4
bestpractical RT=3.8.1-rc5
bestpractical RT=3.8.2
bestpractical RT=3.8.2-rc1
bestpractical RT=3.8.2-rc2
bestpractical RT=3.8.3
bestpractical RT=3.8.3-rc1
bestpractical RT=3.8.3-rc2
bestpractical RT=3.8.4
bestpractical RT=3.8.4-rc1
bestpractical RT=3.8.5
bestpractical RT=3.8.6
bestpractical RT=3.8.6-rc1
bestpractical RT=3.8.7
bestpractical RT=3.8.7-rc1
bestpractical RT=3.8.8
bestpractical RT=3.8.8-rc2
bestpractical RT=3.8.8-rc3
bestpractical RT=3.8.8-rc4
bestpractical RT=3.8.9
bestpractical RT=3.8.9-rc1
bestpractical RT=3.8.9-rc2
bestpractical RT=3.8.9-rc3
bestpractical RT=3.8.10
bestpractical RT=3.8.10-rc1
bestpractical RT=3.8.11
bestpractical RT=3.8.11-rc1
bestpractical RT=3.8.11-rc2
bestpractical RT=3.8.12
bestpractical RT=3.8.13
bestpractical RT=3.8.13-rc1
bestpractical RT=3.8.13-rc2
bestpractical RT=3.8.14
bestpractical RT=3.8.14-rc1
bestpractical RT=3.8.15
bestpractical RT=3.8.16
bestpractical RT=4.0.0
bestpractical RT=4.0.0-rc1
bestpractical RT=4.0.0-rc2
bestpractical RT=4.0.0-rc3
bestpractical RT=4.0.0-rc4
bestpractical RT=4.0.0-rc5
bestpractical RT=4.0.0-rc6
bestpractical RT=4.0.0-rc7
bestpractical RT=4.0.0-rc8
bestpractical RT=4.0.1
bestpractical RT=4.0.1-rc1
bestpractical RT=4.0.1-rc2
bestpractical RT=4.0.2
bestpractical RT=4.0.2-rc1
bestpractical RT=4.0.2-rc2
bestpractical RT=4.0.3
bestpractical RT=4.0.3-rc1
bestpractical RT=4.0.3-rc2
bestpractical RT=4.0.4
bestpractical RT=4.0.5
bestpractical RT=4.0.5-rc1
bestpractical RT=4.0.6
bestpractical RT=4.0.7
bestpractical RT=4.0.7-rc1
bestpractical RT=4.0.8
bestpractical RT=4.0.8-rc1
bestpractical RT=4.0.8-rc2
bestpractical RT=4.0.9
bestpractical RT=4.0.10
bestpractical RT=4.0.11
bestpractical RT=4.0.12
Remediation
Event History
Aug 23, 2013
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-3371?
CVE-2013-3371 is classified as a medium severity vulnerability due to its potential to allow cross-site scripting attacks.
2
How do I fix CVE-2013-3371?
To fix CVE-2013-3371, upgrade to Request Tracker versions 4.0.13 or later.
3
What versions are affected by CVE-2013-3371?
CVE-2013-3371 affects Request Tracker versions 3.8.3 through 3.8.16 and 4.0.x before 4.0.13.
4
What type of vulnerability is CVE-2013-3371?
CVE-2013-3371 is a cross-site scripting (XSS) vulnerability that allows remote code injection via attachment filenames.
5
Can CVE-2013-3371 be exploited remotely?
Yes, CVE-2013-3371 allows remote attackers to inject arbitrary web scripts or HTML.