Trac Denial of Service And Phishing Vulnerabilities
BID:32226
Info
Trac Denial of Service And Phishing Vulnerabilities
| Bugtraq ID: | 32226 |
| Class: | Unknown |
| CVE: |
CVE-2008-5647 CVE-2008-5646 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 08 2008 12:00AM |
| Updated: | Jul 05 2016 10:01PM |
| Credit: | Simon Willison, Matt Murphy |
| Vulnerable: |
Wire One Tanberg 880 0.9.3 Edgewall Software Trac 0.11.1 Edgewall Software Trac 0.9.2 Edgewall Software Trac 0.9.1 Edgewall Software Trac 0.9 Edgewall Software Trac 0.8.4 Edgewall Software Trac 0.8.3 Edgewall Software Trac 0.8.1 Edgewall Software Trac 0.7.1 |
| Not Vulnerable: |
Edgewall Software Trac 0.11.2 |
Discussion
Trac Denial of Service And Phishing Vulnerabilities
Trac is prone to multiple remote vulnerabilities, including a denial-of-service issue and a phishing issue.
Attackers may exploit these issues to perform phishing attacks or cause a denial-of-service condition.
Versions prior to Trac 0.11.2 are vulnerable.
Trac is prone to multiple remote vulnerabilities, including a denial-of-service issue and a phishing issue.
Attackers may exploit these issues to perform phishing attacks or cause a denial-of-service condition.
Versions prior to Trac 0.11.2 are vulnerable.
Exploit / POC
Trac Denial of Service And Phishing Vulnerabilities
Attackers can exploit these issues via a browser.
Attackers can exploit these issues via a browser.
Solution / Fix
Trac Denial of Service And Phishing Vulnerabilities
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
Solution:
The vendor has released updates to address these issues. Please see the references for more information.
References
Trac Denial of Service And Phishing Vulnerabilities
References:
References:
- Trac Change Log 0.11.2 (Edgewall Software)
- Trac Homepage (Trac)