CVE-2005-3980 EXPLOIT
7.5
HIGH · CVSS 2.0 · EPSS 3.3% (pctl 88)
Patch early
A public exploit exists.
Description
SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.
Scoring
| CVSS | 7.5 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
| EPSS | 3.26% — more likely to be exploited than 88% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2005-12-04 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| edgewall software | trac |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Edgewall Software Trac 0.9 Ticket Query Module - SQL Injection | 2005-12-01 |
References
- http://projects.edgewall.com/trac/wiki/ChangeLog
- http://secunia.com/advisories/17836/
- http://securitytracker.com/id?1015302
- http://www.osvdb.org/21386
- http://www.securityfocus.com/archive/1/418294/100/0/threaded
- http://www.securityfocus.com/bid/15676/
- http://www.vupen.com/english/advisories/2005/2701
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23461
- http://projects.edgewall.com/trac/wiki/ChangeLog
- http://secunia.com/advisories/17836/
- http://securitytracker.com/id?1015302
- http://www.osvdb.org/21386
- http://www.securityfocus.com/archive/1/418294/100/0/threaded
- http://www.securityfocus.com/bid/15676/
- http://www.vupen.com/english/advisories/2005/2701
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23461
→ the Explorer · watch your stack · NVD