Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Yoshinari Fukumoto

Researcher fromRakuten, Inc.
#21592of 53,633
11.1Total CVSS
Vulnerabilities · 2
Medium
2
PT-2009-6257
4.3
2009-11-25
Redmine · Redmine · CVE-2009-4078
**Name of the Vulnerable Software and Affected Versions** Redmine versions 0.8.5 and earlier **Description** The issue allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, which can lead to multiple cross-site scripting (XSS) vulnerabilities. **Recommendations** For Redmine versions 0.8.5 and earlier, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2009-6258
6.8
2009-11-25
Redmine · Redmine · CVE-2009-4079
**Name of the Vulnerable Software and Affected Versions** Redmine versions 0.8.5 and earlier **Description** A cross-site request forgery issue allows remote attackers to hijack user authentication for requests, specifically for deleting tickets, via unspecified vectors. **Recommendations** For versions 0.8.5 and earlier, update to a version later than 0.8.5 to resolve the issue.