Unrated severityNVD Advisory· Published Nov 17, 2009· Updated Jun 16, 2026
CVE-2009-3892
CVE-2009-3892
Description
Cross-site scripting (XSS) vulnerability in Best Practical Solutions RT 3.6.x before 3.6.9, 3.8.x before 3.8.5, and other 3.4.6 through 3.8.4 versions allows remote attackers to inject arbitrary web script or HTML via certain Custom Fields.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
16cpe:2.3:a:bestpractical:rt:3.4.6:*:*:*:*:*:*:*+ 15 more
- cpe:2.3:a:bestpractical:rt:3.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.6.0:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.6.2:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.6.3:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.6.4:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.6.5:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.6.6:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.6.7:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.6.8:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.8.0:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.8.3:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt:3.8.4:*:*:*:*:*:*:*
- (no CPE)range: 3.6.x before 3.6.9, 3.8.x before 3.8.5, and other 3.4.6 through 3.8.4 versions
Patches
Vulnerability mechanics
References
5- lists.bestpractical.com/pipermail/rt-announce/2009-September/000172.htmlnvdPatch
- lists.bestpractical.com/pipermail/rt-announce/2009-September/000173.htmlnvdPatch
- bugs.debian.org/cgi-bin/bugreport.cginvd
- www.openwall.com/lists/oss-security/2009/11/15/1nvd
- www.openwall.com/lists/oss-security/2009/11/16/4nvd
News mentions
0No linked articles in our index yet.