Cross-site scripting (XSS) vulnerability in Edgewall Trac 0.9, 0.9.1, and 0.9.2 allows remote attackers to inject arbitrary web script or HTML via the URL, which is not properly sanitized before it is returned in an error page.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 00:03
Type | Values Removed | Values Added |
---|---|---|
References | () http://projects.edgewall.com/trac/wiki/ChangeLog - | |
References | () http://secunia.com/advisories/18048 - Vendor Advisory | |
References | () http://secunia.com/advisories/18625 - | |
References | () http://securitytracker.com/id?1015363 - | |
References | () http://www.gentoo.org/security/en/glsa/glsa-200601-12.xml - | |
References | () http://www.securityfocus.com/bid/16386 - | |
References | () http://www.vupen.com/english/advisories/2005/2936 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/23775 - |
Information
Published : 2005-12-17 00:03
Updated : 2024-11-21 00:03
NVD link : CVE-2005-4305
Mitre link : CVE-2005-4305
CVE.ORG link : CVE-2005-4305
JSON object : View
Products Affected
edgewall_software
- trac
CWE