CVE-2011-1690
Best Practical Solutions RT 3.6.0 through 3.6.10 and 3.8.0 through 3.8.8 allows remote attackers to trick users into sending credentials to an arbitrary server via unspecified vectors.
Date published : 2011-04-22
http://www.securityfocus.com/bid/47383
http://blog.bestpractical.com/2011/04/security-vulnerabilities-in-rt.html