Unrated severityNVD Advisory· Published May 5, 2014· Updated May 6, 2026
CVE-2013-3736
CVE-2013-3736
Description
Cross-site scripting (XSS) vulnerability in the MobileUI (aka RT-Extension-MobileUI) extension before 1.04 in Request Tracker (RT) 4.0.0 before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the name of an attached file.
Affected products
14cpe:2.3:a:bestpractical:request_tracker:4.0.0:*:*:*:*:*:*:*+ 12 more
- cpe:2.3:a:bestpractical:request_tracker:4.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.10:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.11:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.12:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.3:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.4:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.5:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.6:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.7:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.8:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:request_tracker:4.0.9:*:*:*:*:*:*:*
- cpe:2.3:a:bestpractical:rt-extension-mobileui:*:*:*:*:*:*:*:*Range: <=1.02
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.bestpractical.com/pipermail/rt-announce/2013-June/000230.htmlnvdPatchVendor Advisory
- secunia.com/advisories/53799nvdVendor Advisory
- osvdb.org/94281nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/84963nvd
News mentions
0No linked articles in our index yet.