CVE-2008-2951
published 2008-07-27CVE-2008-2951: Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing…
PriorityP419medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
1.83%
76.5th percentile
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | trac | < trac 0.11-1 (sid) | trac 0.11-1 (sid) |
| edgewall | trac | < 0.10.5 | 0.10.5 |
| edgewall | trac | >= 0 < 0.11-1 | 0.11-1 |
| edgewall | trac | >= 0 < 0.10.5 | 0.10.5 |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:P
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Trac Open Redirect vulnerability
ghsa·2022-05-01
CVE-2008-2951 [MEDIUM] CWE-20 Trac Open Redirect vulnerability
Trac Open Redirect vulnerability
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
OSV
Trac Open Redirect vulnerability
osv·2022-05-01
CVE-2008-2951 [MEDIUM] Trac Open Redirect vulnerability
Trac Open Redirect vulnerability
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
OSV
CVE-2008-2951: Open redirect vulnerability in the search script in Trac before 0
osv·2008-07-27·CVSS 6.1
CVE-2008-2951 [MEDIUM] CVE-2008-2951: Open redirect vulnerability in the search script in Trac before 0
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
Red Hat
trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328)
vendor_redhat·2008-06-13·CVSS 6.1
CVE-2008-3328 [MEDIUM] trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328)
trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328)
Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.
Debian
CVE-2008-2951: trac - Open redirect vulnerability in the search script in Trac before 0.10.5 allows re...
vendor_debian·2008·CVSS 6.1
CVE-2008-2951 [MEDIUM] CVE-2008-2951: trac - Open redirect vulnerability in the search script in Trac before 0.10.5 allows re...
Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
Scope: local
sid: resolved (fixed in 0.11-1)
trixie: resolved (fixed in 0.11-1)
No detection rules found.
No public exploits indexed.
arXiv
ThreatZoom: CVE2CWE using Hierarchical Neural Network
arxiv_fulltext·2020-09-24
ThreatZoom: CVE2CWE using Hierarchical Neural Network
ThreatZoom: CVE2CWE using Hierarchical Neural Network
Ehsan Aghaei
Waseem Shadid
Ehab Al-Shaer
Aghaei et al.
University of North Carolina at Charlotte, Charlotte, USA, 28262
\eaghaei, wshadid, ealshaer\@uncc.edu
## Abstract
The Common Vulnerabilities and Exposures (CVE) represent standard means for sharing publicly known information security vulnerabilities. One or more CVEs are grouped into the Common Weakness Enumeration (CWE) classes for the purpose of understanding the software or configuration flaws and potential impacts enabled by these vulnerabilities and identifying means to detect or prevent exploitation.
As the CVE-to-CWE classification is mostly performed manually by domain experts, thousands of critical and new CVEs remain unclassified, yet they are unpatchable. This si
Bugzilla
trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328) [fedora-epel4]
bugzilla·2010-12-23·CVSS 6.1
CVE-2008-2951 [MEDIUM] trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328) [fedora-epel4]
trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328) [fedora-epel4]
+++ This bug was initially created as a clone of Bug #456874 +++
Upstream trac 0.10.5 fixes two non-critical security issues:
http://trac.edgewall.org/wiki/ChangeLog#a0.10.5
CVE-2008-2951:
Open redirect vulnerability in the search script in Trac before 0.10.5
allows remote attackers to redirect users to arbitrary web sites and
conduct phishing attacks via a URL in the q parameter.
References:
http://holisticinfosec.org/content/view/72/45/
http://www.osvdb.org/46513
Upstream patch:
http://trac.edgewall.org/changeset/7224/branches/0.10-stable
CVE-2008-3328:
Cross-site scripting (XSS) vulnerability in the wiki engine in Trac
before 0.10.5 allows remote attackers to inject arbitrary web script
or HTM
Bugzilla
trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328)
bugzilla·2008-07-28·CVSS 6.1
CVE-2008-2951 [MEDIUM] trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328)
trac: multiple security fixes in 0.10.5 (CVE-2008-2951, CVE-2008-3328)
Upstream trac 0.10.5 fixes two non-critical security issues:
http://trac.edgewall.org/wiki/ChangeLog#a0.10.5
CVE-2008-2951:
Open redirect vulnerability in the search script in Trac before 0.10.5
allows remote attackers to redirect users to arbitrary web sites and
conduct phishing attacks via a URL in the q parameter.
References:
http://holisticinfosec.org/content/view/72/45/
http://www.osvdb.org/46513
Upstream patch:
http://trac.edgewall.org/changeset/7224/branches/0.10-stable
CVE-2008-3328:
Cross-site scripting (XSS) vulnerability in the wiki engine in Trac
before 0.10.5 allows remote attackers to inject arbitrary web script
or HTML via unknown vectors.
Upstream patch:
http://trac.edgewall.org/changeset/7207/b
http://holisticinfosec.org/content/view/72/45/http://secunia.com/advisories/31314http://trac.edgewall.org/wiki/ChangeLoghttp://www.osvdb.org/46513http://www.securityfocus.com/bid/30402https://exchange.xforce.ibmcloud.com/vulnerabilities/44043https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01261.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg01270.htmlhttp://holisticinfosec.org/content/view/72/45/http://secunia.com/advisories/31314http://trac.edgewall.org/wiki/ChangeLoghttp://www.osvdb.org/46513http://www.securityfocus.com/bid/30402https://exchange.xforce.ibmcloud.com/vulnerabilities/44043https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01261.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-July/msg01270.html
2008-07-27
Published