Back

CVE-2005-3980

SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier allows remote attackers to execute arbitrary SQL commands via the group parameter.

Published: Dec 4, 2005 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (15)

Vendor Product Version
edgewall_software trac 0.5.1
edgewall_software trac 0.5.2
edgewall_software trac 0.6
edgewall_software trac 0.6.1
edgewall_software trac 0.7
edgewall_software trac 0.7.1
edgewall_software trac 0.8
edgewall_software trac 0.8.1
edgewall_software trac 0.8.2
edgewall_software trac 0.8.3
edgewall_software trac 0.8.4
edgewall_software trac 0.9
edgewall_software trac 0.9b1
edgewall_software trac 0.9b2
edgewall_software trac 0.50.9

GitHub Security Advisory GHSA-jphx-j9jw-r6cr

SQL injection vulnerability in the ticket query module in Edgewall Trac 0.9 and possibly earlier...

Risk Scores

CVSS Score 7.5 / 10
EPSS Score 3.26%

Top 13% most likely to be exploited

Threat Score 31 / 100

Data Sources

NVD EPSS GitHub