Vulnerabilities > CVE-2007-1406 - Remote Security vulnerability in Trac
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors. This vulnerability has been addressed by the following vendor update: http://trac.edgewall.org/wiki/TracDownload
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 4 |