{"id":"PYSEC-2007-3","details":"Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain \"unsafe\" situations, which has unknown impact and remote attack vectors.","aliases":["CVE-2007-1406","GHSA-7jjr-3r8r-9pcf"],"modified":"2026-06-10T17:02:44.828761407Z","published":"2007-03-10T22:19:00Z","references":[{"type":"WEB","url":"http://trac.edgewall.org/wiki/ChangeLog"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-7jjr-3r8r-9pcf"}],"affected":[{"package":{"name":"trac","ecosystem":"PyPI","purl":"pkg:pypi/trac"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.3.1"}]}],"versions":["0.10","0.8.4","0.9"],"database_specific":{"source":"https://github.com/pypa/advisory-database/blob/main/vulns/trac/PYSEC-2007-3.yaml"}}],"schema_version":"1.7.5"}