GHSA-6vhp-hp77-6w52
Dashboard / Vulnerabilities / GHSA-6vhp-hp77-6w52
GHSA-6vhp-hp77-6w52
Summary: Trac HTML WikiProcessor cross-site scripting (XSS) vulnerability
Details: Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.
References: https://nvd.nist.gov/vuln/detail/CVE-2005-4644, https://exchange.xforce.ibmcloud.com/vulnerabilities/24183, https://github.com/pypa/advisory-database/tree/main/vulns/trac/PYSEC-2005-1.yaml, https://web.archive.org/web/20140722192945/http://secunia.com/advisories/18465, https://web.archive.org/web/20151104154255/http://secunia.com/advisories/18555, https://web.archive.org/web/20200302063657/http://www.securityfocus.com/bid/16198, http://projects.edgewall.com/trac/ticket/2473, http://trac.edgewall.org/ticket/2473, http://www.debian.org/security/2006/dsa-951
Affected packages
Package
Name: trac
Purl: pkg:pypi/trac
Affected ranges
Type: ECOSYSTEM
Events:
