CVE-2013-3372: XSS
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject multiple Content-Disposition HTTP headers and possibly conduct cross-site scripting (XSS) attacks via unspecified vectors.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-3372?
CVE-2013-3372 has been classified as a moderate severity vulnerability.
What are the affected versions in CVE-2013-3372?
CVE-2013-3372 affects Request Tracker versions 3.8.x before 3.8.17 and 4.0.x before 4.0.13.
How do I fix CVE-2013-3372?
To fix CVE-2013-3372, upgrade your Request Tracker to version 3.8.17 or 4.0.13 or later.
Can CVE-2013-3372 lead to XSS attacks?
Yes, CVE-2013-3372 allows for multiple Content-Disposition HTTP headers, which can potentially lead to cross-site scripting (XSS) attacks.
What is the main issue with CVE-2013-3372?
The main issue with CVE-2013-3372 is that it allows remote attackers to inject multiple HTTP headers, potentially compromising user security.