Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2007-1405

Опубликовано: 10 мар. 2007
Источник: debian
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
tracfixed0.10.3-1etch1etchpackage
tracfixed0.10.4-1package

Примечания

  • Browser bug, only exploitable on IE, still fixed in a point release

EPSS

Процентиль: 57%
0.00351
Низкий

Связанные уязвимости

ubuntu
больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

nvd
больше 18 лет назад

Cross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.

CVSS3: 6.1
github
больше 3 лет назад

Trac Cross-site Scripting (XSS) vulnerability

EPSS

Процентиль: 57%
0.00351
Низкий