Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter, possibly related to the quickjump function.
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01270.html
https://www.redhat.com/archives/fedora-package-announce/2008-July/msg01261.html