CVE-2013-3369
Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote authenticated users with the permissions to view the administration pages to execute arbitrary private components via unspecified vectors.
Date published : 2013-08-23
http://www.debian.org/security/2012/dsa-2670
http://lists.bestpractical.com/pipermail/rt-announce/2013-May/000228.html