CVE-2006-3695: XSS
Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-3695?
CVE-2006-3695 is considered a medium severity vulnerability due to its potential for remote exploitation and impact on user data.
How do I fix CVE-2006-3695?
To fix CVE-2006-3695, upgrade Trac to version 0.9.6 or later.
What software is affected by CVE-2006-3695?
CVE-2006-3695 affects Trac versions prior to 0.9.6.
What types of attacks can be executed due to CVE-2006-3695?
CVE-2006-3695 can be exploited to read arbitrary files, perform XSS attacks, or cause denial of service.
Is there a known exploit for CVE-2006-3695?
Yes, CVE-2006-3695 is known to be exploitable by remote attackers, making it crucial to apply the necessary updates.