Safety vulnerability ID: 53918
The information on this page was manually curated by our Cybersecurity Intelligence Team.
Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458.
Latest version: 1.6
Integrated SCM, wiki, issue tracker and project environment
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application