Edgewall Software / Trac
15 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2010-5108 | Trac 0.11.6 does not properly check workflow permissions before modifying a ticket. This can be exploited by an attacker to change the status and resolution of… | HIGH | 7.5 | Nov 13, 2019 |
| CVE-2009-4405 | Multiple unspecified vulnerabilities in Trac before 0.11.6 have unknown impact and attack vectors, possibly related to (1) "policy checks in report results whe… | HIGH | 8.7 | Dec 23, 2009 |
| CVE-2008-3328 | trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328) | MEDIUM | 5.3 | Jul 27, 2008 |
| CVE-2008-2951 | Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing at… | MEDIUM | 5.3 | Jul 27, 2008 |
| CVE-2007-1406 | Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remo… | MEDIUM | 6.9 | Mar 10, 2007 |
| CVE-2007-1405 | Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows… | MEDIUM | 5.3 | Mar 10, 2007 |
| CVE-2006-5878 | Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as other users via un… | HIGH | 8.7 | Nov 14, 2006 |
| CVE-2006-3695 | Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from… | HIGH | 8.8 | Jul 19, 2006 |
| CVE-2006-2106 | Cross-site scripting (XSS) vulnerability in Edgewall Software Trac 0.9.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown… | MEDIUM | 4.3 | Apr 29, 2006 |
| CVE-2005-4644 | Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via ja… | MEDIUM | 5.3 | Jan 11, 2006 |
| CVE-2005-4305 | Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, whi… | MEDIUM | 4.3 | Dec 17, 2005 |
| CVE-2005-4065 | SQL injection vulnerability in the search module in Edgewall Trac before 0.9.2 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | HIGH | 7.5 | Dec 7, 2005 |
| CVE-2005-3980 | SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via… | HIGH | 7.5 | Dec 4, 2005 |
| CVE-2005-2147 | Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer… | MEDIUM | 6.4 | Jul 6, 2005 |
| CVE-2005-2007 | Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id para… | MEDIUM | 6.4 | Jun 20, 2005 |
Showing 1 to 15 of 15 CVEs