10
CVSSv2

CVE-2007-1406

Published: 10/03/2007 Updated: 05/09/2008
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Trac prior to 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.

Vulnerable Product Search on Vulmon Subscribe to Product

edgewall software trac 0.10.2

edgewall software trac 0.10

edgewall software trac 0.10.1

edgewall software trac 0.10.3

Vendor Advisories

Debian Bug report logs - #414134 CSS and remote exploitable security issues Package: trac; Maintainer for trac is Python Applications Packaging Team <python-apps-team@listsaliothdebianorg>; Source for trac is src:trac (PTS, buildd, popcon) Reported by: "Cort, Tom" <TomCort@statevtus> Date: Fri, 9 Mar 2007 12:3 ...