| Vulnerability Name: | CVE-2005-4644 (CCN-24183) | ||||||||
| Assigned: | 2005-12-31 | ||||||||
| Published: | 2005-12-31 | ||||||||
| Updated: | 2017-07-20 | ||||||||
| Summary: | Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag. | ||||||||
| CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
| CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N)
| ||||||||
| Vulnerability Type: | CWE-Other | ||||||||
| Vulnerability Consequences: | Gain Access | ||||||||
| References: | Source: MITRE Type: CNA CVE-2005-4644 Source: CCN Type: Trac Web site The Trac Project - Trac Source: CONFIRM Type: Exploit, Patch, Vendor Advisory http://projects.edgewall.com/trac/ticket/2473 Source: CCN Type: Trac - Integrated SCM & Project Management Trac Download - Latest Stable Release - 0.9.3 Source: CCN Type: SA18465 Trac HTML WikiProcessor Script Insertion Vulnerability Source: SECUNIA Type: UNKNOWN 18465 Source: SECUNIA Type: UNKNOWN 18555 Source: CONFIRM Type: UNKNOWN http://trac.edgewall.org/ticket/2473 Source: DEBIAN Type: UNKNOWN DSA-951 Source: DEBIAN Type: DSA-951 trac -- missing input sanitising Source: CCN Type: OSVDB ID: 22273 Trac HTML WikiProcessor XSS Source: BID Type: Patch 16198 Source: CCN Type: BID-16198 Edgewall Software Trac HTML WikiProcessor Wiki Content HTML Injection Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-0226 Source: XF Type: UNKNOWN trac-html-xss(24183) Source: XF Type: UNKNOWN trac-html-xss(24183) | ||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
| Oval Definitions | |||||||||
| |||||||||
| BACK | |||||||||