4.3
CVSSv2

CVE-2007-1405

Published: 10/03/2007 Updated: 29/07/2017
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac prior to 0.10.3.1, when Microsoft Internet Explorer is used, allows remote malicious users to inject arbitrary web script or HTML via unspecified parameters.

Vulnerable Product Search on Vulmon Subscribe to Product

edgewall software trac 0.10

edgewall software trac 0.10.3

edgewall software trac 0.10.1

edgewall software trac 0.10.2

Vendor Advisories

Debian Bug report logs - #414134 CSS and remote exploitable security issues Package: trac; Maintainer for trac is Python Applications Packaging Team <python-apps-team@listsaliothdebianorg>; Source for trac is src:trac (PTS, buildd, popcon) Reported by: "Cort, Tom" <TomCort@statevtus> Date: Fri, 9 Mar 2007 12:3 ...