CVE-2007-1406

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/03/2007
Last modified:
09/04/2025

Description

Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:edgewall_software:trac:0.10:*:*:*:*:*:*:*
cpe:2.3:a:edgewall_software:trac:0.10.1:*:*:*:*:*:*:*
cpe:2.3:a:edgewall_software:trac:0.10.2:*:*:*:*:*:*:*
cpe:2.3:a:edgewall_software:trac:0.10.3:*:*:*:*:*:*:*