|
|
Log in / Subscribe / Register

trac: cross-site scripting vulnerability

Package(s):trac CVE #(s):CVE-2005-4305
Created:January 26, 2006 Updated:February 1, 2006
Description: Trac, a web-based project management and bug tracking system, has a cross-site scripting attack vulnerability that may be exploited for the purpose of execution of arbitrary JavaScript code.
Alerts:
Gentoo 200601-12 trac 2006-01-26

to post comments

trac: cross-site scripting vulnerability

Posted Feb 2, 2006 14:09 UTC (Thu) by wingo (guest, #26929) [Link]

See my comments on http://lwn.net/Articles/168831/ -- this appears to have been fixed upstream for almost a month now. The created date is still misleading. The release went out with full disclosure a long time ago.


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds