HIGH
Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors
Published Jul 19, 2006
8.8
HIGHCVSS 4.0
EPSS 1.90%
Description
Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458.
Affected products
No data.
- ≤ 0.9.5
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (16)
- http://secunia.com/advisories/20958 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21534 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://securitytracker.com/id?1016457 vdb-entryx_refsource_SECTRACK
- http://trac.edgewall.org/wiki/ChangeLog x_refsource_CONFIRM
- http://www.debian.org/security/2006/dsa-1152 vendor-advisoryx_refsource_DEBIAN
- http://www.securityfocus.com/bid/18323 vdb-entryx_refsource_BID
- http://www.vupen.com/english/advisories/2006/2729 vdb-entryx_refsource_VUPENVendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27706 vdb-entryx_refsource_XF
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27708 vdb-entryx_refsource_XF
- https://github.com/advisories/GHSA-r524-c2gf-5chr Advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/trac/PYSEC-2006-2.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2006-3695
- https://web.archive.org/web/20061227230548/http://trac.edgewall.org/wiki/ChangeLog
- https://web.archive.org/web/20140804165436/http://secunia.com/advisories/21534
- https://web.archive.org/web/20140806223337/http://secunia.com/advisories/20958
- https://web.archive.org/web/20200228034827/http://www.securityfocus.com/bid/18323
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 19, 2006
Updated Aug 7, 2024
Reserved Jul 18, 2006
Link CVE-2006-3695
CISA Vulnrichment
GHSA-R524-C2GF-5CHR Updated n/a