6.8

CVE-2006-3695

Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Edgewall SoftwareTrac Version <= 0.9.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.86% 0.765
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.securityfocus.com/bid/18323
http://secunia.com/advisories/20958
Vendor Advisory
http://secunia.com/advisories/21534
Vendor Advisory
http://securitytracker.com/id?1016457
http://trac.edgewall.org/wiki/ChangeLog
http://www.debian.org/security/2006/dsa-1152
http://www.vupen.com/english/advisories/2006/2729
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/27706
https://exchange.xforce.ibmcloud.com/vulnerabilities/27708