CVE
- Id
- 48919
- CVE No.
- CVE-2011-1007
- Status
- Candidate
- Description
- Best Practical Solutions RT before 3.8.9 does not perform certain redirect actions upon a login, which allows physically proximate attackers to obtain credentials by resubmitting the login form via the back button of a web browser on an unattended workstation after an RT logout.
- Phase
- Assigned (20110214)
- Votes
- None (candidate not yet proposed)
- Comments
Related CVE References
Id | CVE Id | CVE No. | Reference | Actions |
---|---|---|---|---|
531270 | 48919 | CVE-2011-1007 | MLIST:[oss-security] 20110222 CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition | View |
531271 | 48919 | CVE-2011-1007 | URL:http://openwall.com/lists/oss-security/2011/02/22/6 | View |
531272 | 48919 | CVE-2011-1007 | MLIST:[oss-security] 20110222 Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition | View |
531273 | 48919 | CVE-2011-1007 | URL:http://openwall.com/lists/oss-security/2011/02/22/12 | View |
531274 | 48919 | CVE-2011-1007 | MLIST:[oss-security] 20110222 Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition | View |
531275 | 48919 | CVE-2011-1007 | URL:http://openwall.com/lists/oss-security/2011/02/22/16 | View |
531276 | 48919 | CVE-2011-1007 | MLIST:[oss-security] 20110223 Re: Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition | View |
531277 | 48919 | CVE-2011-1007 | URL:http://openwall.com/lists/oss-security/2011/02/23/22 | View |
531278 | 48919 | CVE-2011-1007 | MLIST:[oss-security] 20110224 Re: Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition | View |
531279 | 48919 | CVE-2011-1007 | URL:http://openwall.com/lists/oss-security/2011/02/24/7 | View |
531280 | 48919 | CVE-2011-1007 | MLIST:[oss-security] 20110224 Re: Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition | View |
531281 | 48919 | CVE-2011-1007 | URL:http://openwall.com/lists/oss-security/2011/02/24/8 | View |
531282 | 48919 | CVE-2011-1007 | MLIST:[oss-security] 20110224 Re: Re: CVE Request -- rt3 -- two issues: 1) Improper management of form data resubmittion upon user log out 2) SQL queries information leak by user account transition | View |
531283 | 48919 | CVE-2011-1007 | URL:http://openwall.com/lists/oss-security/2011/02/24/9 | View |
531284 | 48919 | CVE-2011-1007 | MLIST:[rt-announce] 20110216 RT 3.8.9 Released | View |
531285 | 48919 | CVE-2011-1007 | URL:http://lists.bestpractical.com/pipermail/rt-announce/2011-February/000186.html | View |
531286 | 48919 | CVE-2011-1007 | CONFIRM:http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=614575 | View |
531287 | 48919 | CVE-2011-1007 | CONFIRM:http://issues.bestpractical.com/Ticket/Display.html?id=15804 | View |
531288 | 48919 | CVE-2011-1007 | CONFIRM:https://github.com/bestpractical/rt/commit/057552287159e801535e59b8fbd5bd98d1322069 | View |
531289 | 48919 | CVE-2011-1007 | CONFIRM:https://github.com/bestpractical/rt/commit/917c211820590950f7eb0521f7f43b31aeed44c4 | View |
531290 | 48919 | CVE-2011-1007 | OSVDB:71012 | View |
531291 | 48919 | CVE-2011-1007 | URL:http://osvdb.org/71012 | View |
531292 | 48919 | CVE-2011-1007 | SECUNIA:43438 | View |
531293 | 48919 | CVE-2011-1007 | URL:http://secunia.com/advisories/43438 | View |
531294 | 48919 | CVE-2011-1007 | VUPEN:ADV-2011-0475 | View |
531295 | 48919 | CVE-2011-1007 | URL:http://www.vupen.com/english/advisories/2011/0475 | View |
531296 | 48919 | CVE-2011-1007 | XF:rt-login-information-disclosure(65771) | View |
Related JVN
Id | JVN No. | Title | Summary | CVE No. | CVE Id | CVSS_v2 | CVSS_v3 | JVN URL | Actions |
---|---|---|---|---|---|---|---|---|---|
34052 | JVNDB-2011-004294 | Linux kernel の ldm_parse_vmdb 関数におけるサービス運用妨害 (DoS) の脆弱性 | Linux kernel の fs/partitions/ldm.c の ldm_parse_vmdb 関数は、LDM パーティションテーブルの VMDB 構造の VBLK サイズ値を検証しないため、サービス運用妨害 (ゼロ除算エラーおよび OOPS) 状態となる脆弱性が存在します。 | CVE-2011-1012 | 48919 | 4.9 | http://jvndb.jvn.jp/ja/contents/2011/JVNDB-2011-004294.html | View |