CVE-2007-1406
Trac < 0.10.3.1 - Unsafe Content-Disposition Header Handling
Title source: llmDescription
Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.
References (1)
Core 1
Core References
Third Party Advisory x_refsource_confirm
http://trac.edgewall.org/wiki/ChangeLog
Scores
EPSS
0.0134
EPSS Percentile
68.4%
Details
Status
published
Products (5)
edgewall_software/trac
0.10
edgewall_software/trac
0.10.1
edgewall_software/trac
0.10.2
edgewall_software/trac
0.10.3
pypi/trac
0 - 0.10.3.1PyPI
Published
Mar 10, 2007
Tracked Since
Feb 18, 2026