CVE-2006-3695
Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting…
Does this matter?
Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.
Description
Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.90% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- edgewall software/trac
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/20958Vendor Advisory
- http://secunia.com/advisories/21534Vendor Advisory
- http://securitytracker.com/id?1016457
- http://trac.edgewall.org/wiki/ChangeLog
- http://www.debian.org/security/2006/dsa-1152
- http://www.securityfocus.com/bid/18323
- http://www.vupen.com/english/advisories/2006/2729Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27706
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27708
- http://secunia.com/advisories/20958Vendor Advisory
- http://secunia.com/advisories/21534Vendor Advisory
- http://securitytracker.com/id?1016457
- http://trac.edgewall.org/wiki/ChangeLog
- http://www.debian.org/security/2006/dsa-1152
- http://www.securityfocus.com/bid/18323
- http://www.vupen.com/english/advisories/2006/2729Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27706
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27708
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.