Gentoo Linux Security Advisory GLSA 200601-12 https://security.gentoo.org/ Severity: Low Title: Trac: Cross-site scripting vulnerability Date: January 26, 2006 Bugs: #118302 ID: 200601-12
Synopsis
=======
Trac is vulnerable to a cross-site scripting attack that could allow
arbitrary JavaScript code execution.
Background
=========
Trac is a minimalistic web-based project management, wiki and bug
tracking system including a Subversion interface.
Affected packages
================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 www-apps/trac < 0.9.3 >= 0.9.3
==========
Christophe Truc discovered that Trac fails to properly sanitize input
passed in the URL.
Impact
=====
A remote attacker ...
style>.gentoo_availability{display:block;}
Get the latest Linux and open source security news straight to your inbox.