Executive brief
Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.
Affected products
- PyPI trac
Junglewise Threat Intelligence
CVE-2007-1406 · Severity: low · CVSS 3.1 · Published 2007-03-10
Technologies: trac (PyPI). Vendors: PyPI.
Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.