FAQ manager for Request Tracker (RTFM) before 2.4.5 does not properly check user rights, which allows remote authenticated users to create arbitrary articles in arbitrary classes via unknown vectors.
http://www.debian.org/security/2012/dsa-2568
http://secunia.com/advisories/51111
http://secunia.com/advisories/51062
http://lists.bestpractical.com/pipermail/rt-announce/2012-October/000215.html
http://lists.bestpractical.com/pipermail/rt-announce/2012-October/000212.html