Vulnerabilities > CVE-2006-2106 - Remote HTML Injection vulnerability in Edgewall Software Trac 0.9.4
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE network
edgewall-software
Summary
Cross-site scripting (XSS) vulnerability in Edgewall Software Trac 0.9.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors related to a "wiki macro."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
References
- http://jvn.jp/jp/JVN%2384091359/index.html
- http://secunia.com/advisories/19870
- http://securitytracker.com/id?1015986
- http://www.edgewall.com/blog/news/trac_0_9_5.html
- http://www.securityfocus.com/bid/17741
- http://www.vupen.com/english/advisories/2006/1557
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26125