CVE detail
CVE-2006-3695 — CVE-2006-3695
Published 2006-07-21 · Modified 2026-06-16 · Vendor edgewall_software · Product trac · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0186
EPSS probability
exploitation probability, 30d
77.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References