DSA-1152-1 reports another vulnerability, this time fixed in Trac 0.9.6: http://www.debian.org/security/2006/dsa-1152 -- Trac 0.9.1 and 0.9.2 to fix SQL injection vulnerabilities, 0.9.3 – XSS vulnerabilities https://launchpad.net/bugs/5297