Vulnerability index

Browse CVEs

7 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Trac HIGH 10.0
CVE-2007-1406

Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impac…

Mitigation only
Fix from $1,950 2007-03-10
Trac HIGH 7.5
CVE-2006-5878

Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as other us…

Fix: after 0.10
Fix from $1,950 2006-11-14
Trac MEDIUM 6.8
CVE-2006-3695

Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functiona…

Fix: after 0.9.5
Fix from $1,600 2006-07-21
Trac HIGH 7.5
CVE-2005-4065

SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown …

Patch available
Fix from $1,950 2005-12-07
Trac HIGH 7.5
CVE-2005-3980

SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL com…

Patch available
Fix from $1,950 2005-12-04
Trac MEDIUM 6.4
CVE-2005-2147

Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachme…

Patch available
Fix from $1,600 2005-07-06
Trac MEDIUM 6.4
CVE-2005-2007

Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in t…

Patch available
Fix from $1,600 2005-06-19