SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Trac | Edgewall_software | 0.5.1 (including) | 0.5.1 (including) |
Trac | Edgewall_software | 0.5.2 (including) | 0.5.2 (including) |
Trac | Edgewall_software | 0.6 (including) | 0.6 (including) |
Trac | Edgewall_software | 0.6.1 (including) | 0.6.1 (including) |
Trac | Edgewall_software | 0.7 (including) | 0.7 (including) |
Trac | Edgewall_software | 0.7.1 (including) | 0.7.1 (including) |
Trac | Edgewall_software | 0.8 (including) | 0.8 (including) |
Trac | Edgewall_software | 0.8.1 (including) | 0.8.1 (including) |
Trac | Edgewall_software | 0.8.2 (including) | 0.8.2 (including) |
Trac | Edgewall_software | 0.8.3 (including) | 0.8.3 (including) |
Trac | Edgewall_software | 0.8.4 (including) | 0.8.4 (including) |
Trac | Edgewall_software | 0.9 (including) | 0.9 (including) |
Trac | Edgewall_software | 0.9b1 (including) | 0.9b1 (including) |
Trac | Edgewall_software | 0.9b2 (including) | 0.9b2 (including) |
Trac | Edgewall_software | 0.50.9 (including) | 0.50.9 (including) |