Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Yoshinari Fukumoto

Pesquisador deRakuten, Inc.
#21595de 53,635
11.1CVSS total
Vulnerabilidades · 2
Média
2
PT-2009-6257
4.3
2009-11-25
Redmine · Redmine · CVE-2009-4078
**Name of the Vulnerable Software and Affected Versions** Redmine versions 0.8.5 and earlier **Description** The issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which can lead to multiple cross-site scripting (XSS) vulnerabilities. **Recommendations** For Redmine versions 0.8.5 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2009-6258
6.8
2009-11-25
Redmine · Redmine · CVE-2009-4079
**Name of the Vulnerable Software and Affected Versions** Redmine versions 0.8.5 and earlier **Description** A cross-site request forgery issue allows remote attackers to hijack user authentication for requests, specifically for deleting tickets, via unspecified vectors. **Recommendations** For versions 0.8.5 and earlier, update to a version later than 0.8.5 to resolve the issue.