Vulnerable Systems:
* Redmine Redmine 1.0.4 and prior
Exploiting these issues could allow an attacker to gain access to potentially sensitive information, inject arbitrary HTML code into the application, steal cookie-based authentication credentials, and execute arbitrary commands in the context of the webserver.
Vendor Status:
Vendor as issued an updated vulnerability.