Vulnerabilities > CVE-2005-4644 - Unspecified vulnerability in Edgewall Software Trac 0.9.2
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN edgewall-software
nessus
Summary
Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Nessus
NASL family | Debian Local Security Checks |
NASL id | DEBIAN_DSA-951.NASL |
description | This update corrects the search feature in trac, an enhanced wiki and issue tracking system for software development projects, which broke with the last security update. For completeness please find below the original advisory text : Several vulnerabilities have been discovered in trac, an enhanced wiki and issue tracking system for software development projects. The Common Vulnerabilities and Exposures project identifies the following problems : - CVE-2005-4065 Due to missing input sanitising it is possible to inject arbitrary SQL code into the SQL statements. - CVE-2005-4644 A cross-site scripting vulnerability has been discovered that allows remote attackers to inject arbitrary web script or HTML. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 22817 |
published | 2006-10-14 |
reporter | This script is Copyright (C) 2006-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/22817 |
title | Debian DSA-951-2 : trac - missing input sanitising |
code |
|
References
- http://projects.edgewall.com/trac/ticket/2473
- http://projects.edgewall.com/trac/ticket/2473
- http://secunia.com/advisories/18465
- http://secunia.com/advisories/18465
- http://secunia.com/advisories/18555
- http://secunia.com/advisories/18555
- http://trac.edgewall.org/ticket/2473
- http://trac.edgewall.org/ticket/2473
- http://www.debian.org/security/2006/dsa-951
- http://www.debian.org/security/2006/dsa-951
- http://www.securityfocus.com/bid/16198
- http://www.securityfocus.com/bid/16198
- http://www.vupen.com/english/advisories/2006/0226
- http://www.vupen.com/english/advisories/2006/0226
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24183
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24183