Trac
Edgewall Software · 15 CVEs
Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacke…
Nov 13, 2019
Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to…
Dec 23, 2009
trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328)
Jul 27, 2008
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arb…
Jul 27, 2008
Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situa…
Mar 10, 2007
Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Micr…
Mar 10, 2007
Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform un…
Nov 14, 2006
Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured tex…
Jul 19, 2006
Cross-site scripting (XSS) vulnerability in Edgewall Software Trac 0.9.4 and earlier allows remote attackers to inject…
Apr 29, 2006
Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to in…
Jan 11, 2006
Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbit…
Dec 17, 2005
SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbit…
Dec 7, 2005
SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attacker…
Dec 4, 2005
Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to…
Jul 6, 2005
Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary…
Jun 20, 2005
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2010-5108 | Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of… | HIGH | 1.30% | Nov 13, 2019 |
| CVE-2009-4405 | Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results whe… | HIGH | 1.97% | Dec 23, 2009 |
| CVE-2008-3328 | trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328) | MEDIUM | 1.33% | Jul 27, 2008 |
| CVE-2008-2951 | Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at… | MEDIUM | 1.83% | Jul 27, 2008 |
| CVE-2007-1406 | Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remo… | MEDIUM | 1.41% | Mar 10, 2007 |
| CVE-2007-1405 | Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows… | MEDIUM | 1.15% | Mar 10, 2007 |
| CVE-2006-5878 | Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as other users via un… | HIGH | 2.14% | Nov 14, 2006 |
| CVE-2006-3695 | Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from… | HIGH | 1.90% | Jul 19, 2006 |
| CVE-2006-2106 | Cross-site scripting (XSS) vulnerability in Edgewall Software Trac 0.9.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown… | MEDIUM | 1.37% | Apr 29, 2006 |
| CVE-2005-4644 | Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via ja… | MEDIUM | 1.52% | Jan 11, 2006 |
| CVE-2005-4305 | Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, whi… | MEDIUM | 1.44% | Dec 17, 2005 |
| CVE-2005-4065 | SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | HIGH | 3.98% | Dec 7, 2005 |
| CVE-2005-3980 | SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via… | HIGH | 3.26% | Dec 4, 2005 |
| CVE-2005-2147 | Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer… | MEDIUM | 1.42% | Jul 6, 2005 |
| CVE-2005-2007 | Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id para… | MEDIUM | 1.79% | Jun 20, 2005 |
Showing 1 to 15 of 15 CVEs