« Volver al listado

CVE-2007-1406

Estado: ModificadaAlta (10)—

Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-1406",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-03-10T22:19:00.000",
  "references": [
    {
      "url": "http://trac.edgewall.org/wiki/ChangeLog",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://trac.edgewall.org/wiki/ChangeLog",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain \"unsafe\" situations, which has unknown impact and remote attack vectors."
    },
    {
      "lang": "es",
      "value": "Trac anterior a 0.10.3.1 no envía una cabecera de disposición de contenido HTTP especificando un adjunto en ciertas situaciones \"no seguras\", lo cual tiene un impacto desconocido y vectores de ataque remotos."
    }
  ],
  "lastModified": "2026-06-16T22:37:31.433",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:edgewall_software:trac:0.10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "380AFEFF-64A3-43A7-8EBB-88829039A9EC"
            },
            {
              "criteria": "cpe:2.3:a:edgewall_software:trac:0.10.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "541460F8-30BC-40B3-ADE7-A0C8FAC7C34E"
            },
            {
              "criteria": "cpe:2.3:a:edgewall_software:trac:0.10.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "393BF6C4-B455-4DDE-9A29-794AF3900F60"
            },
            {
              "criteria": "cpe:2.3:a:edgewall_software:trac:0.10.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9DF703B1-B485-4D16-90C9-820A2780AE2C"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "This vulnerability has been addressed by the following vendor update:\r\nhttp://trac.edgewall.org/wiki/TracDownload",
  "sourceIdentifier": "cve@mitre.org"
}