LWN.net Logo

trac: multiple vulnerabilities

Package(s):trac CVE #(s):CVE-2008-2951 CVE-2008-3328
Created:July 31, 2008 Updated:August 6, 2008
Description: The trac integrated software management system has two vulnerabilities. From the Fedora alert:

CVE-2008-2951: Open redirect vulnerability in the search script in Trac before 0.10.5 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the q parameter.

CVE-2008-3328: Cross-site scripting (XSS) vulnerability in the wiki engine in Trac before 0.10.5 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

Alerts:
Fedora FEDORA-2008-6833 2008-07-30

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds