CVE-2006-5878: CSRF
Published Nov 14, 2006
·Updated
Cross-site request forgery (CSRF) vulnerability in Edgewall Trac 0.10 and earlier allows remote attackers to perform unauthorized actions as other users via unknown vectors.
Affected Software
24 affected componentsFixes available
pip/trac<0.10.1
0.10.1
Edgewall Software Trac<=0.10
Edgewall Software Trac=0.5
Edgewall Software Trac=0.5.1
Edgewall Software Trac=0.5.2
Edgewall Software Trac=0.6
Edgewall Software Trac=0.6.1
Edgewall Software Trac=0.7
Edgewall Software Trac=0.7.1
Edgewall Software Trac=0.8
Edgewall Software Trac=0.8.1
Edgewall Software Trac=0.8.2
Edgewall Software Trac=0.8.3
Edgewall Software Trac=0.8.4
Edgewall Software Trac=0.9
Edgewall Software Trac=0.9.1
Edgewall Software Trac=0.9.2
Edgewall Software Trac=0.9.3
Edgewall Software Trac=0.9.4
Edgewall Software Trac=0.9.5
Edgewall Software Trac=0.9.6
Edgewall Software Trac=0.9b1
Edgewall Software Trac=0.9b2
Edgewall Software Trac=0.50.9
Remediation
Patch Available
Patch Available
Event History
Nov 14, 2006
CVE Published
07:07 PM
Data Sourced
via NVD·07:07 PM
RemedyDescriptionSeverityAffected Software
Nov 15, 2006
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
May 1, 2022
Advisory Published
via GitHub·07:32 AM
Frequently Asked Questions
1
What is the severity of CVE-2006-5878?
CVE-2006-5878 has a moderate severity level due to its potential for unauthorized actions through cross-site request forgery.
2
How do I fix CVE-2006-5878?
To fix CVE-2006-5878, upgrade to Trac version 0.10.1 or later.
3
Which versions of Edgewall Trac are affected by CVE-2006-5878?
CVE-2006-5878 affects Edgewall Trac versions 0.10 and earlier.
4
What type of vulnerability is CVE-2006-5878?
CVE-2006-5878 is classified as a cross-site request forgery (CSRF) vulnerability.
5
Can attackers exploit CVE-2006-5878 remotely?
Yes, attackers can exploit CVE-2006-5878 remotely to perform unauthorized actions as other users.