CVE-2005-4644

Trac 0.9.2 - Cross-Site Scripting via IMG Tag SRC Attribute

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.

References (8)

Core 8
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18555
Various Sources x_refsource_confirm
http://trac.edgewall.org/ticket/2473
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/24183
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/18465
Exploit, Patch, Vendor Advisory x_refsource_confirm
http://projects.edgewall.com/trac/ticket/2473
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0226
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/16198
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2006/dsa-951

Scores

EPSS 0.0151
EPSS Percentile 71.8%

Details

Status published
Products (2)
edgewall_software/trac 0.9.2
pypi/trac 0 - 0.9-stablePyPI
Published Dec 31, 2005
Tracked Since Feb 18, 2026