CVE-2007-1406

Trac < 0.10.3.1 - Unsafe Content-Disposition Header Handling

Title source: llm
STIX 2.1

Description

Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.

References (1)

Core 1
Core References
Third Party Advisory x_refsource_confirm
http://trac.edgewall.org/wiki/ChangeLog

Scores

EPSS 0.0134
EPSS Percentile 68.4%

Details

Status published
Products (5)
edgewall_software/trac 0.10
edgewall_software/trac 0.10.1
edgewall_software/trac 0.10.2
edgewall_software/trac 0.10.3
pypi/trac 0 - 0.10.3.1PyPI
Published Mar 10, 2007
Tracked Since Feb 18, 2026