{"id":"CVE-2005-3980","details":"SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.","modified":"2026-04-10T03:38:17.525271Z","published":"2005-12-04T11:03:00Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/17836/"},{"type":"ADVISORY","url":"http://securitytracker.com/id?1015302"},{"type":"ADVISORY","url":"http://www.vupen.com/english/advisories/2005/2701"},{"type":"EVIDENCE","url":"http://securitytracker.com/id?1015302"},{"type":"EVIDENCE","url":"http://www.securityfocus.com/bid/15676/"},{"type":"FIX","url":"http://secunia.com/advisories/17836/"},{"type":"FIX","url":"http://securitytracker.com/id?1015302"},{"type":"FIX","url":"http://www.securityfocus.com/bid/15676/"},{"type":"WEB","url":"http://projects.edgewall.com/trac/wiki/ChangeLog"},{"type":"WEB","url":"http://www.osvdb.org/21386"},{"type":"WEB","url":"http://www.securityfocus.com/archive/1/418294/100/0/threaded"},{"type":"WEB","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/23461"}],"schema_version":"1.7.5"}