CVE-2006-2106

NameCVE-2006-2106
DescriptionCross-site scripting (XSS) vulnerability in Edgewall Software Trac 0.9.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors related to a "wiki macro."
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
trac (PTS)buster1.2.3+dfsg-1fixed
sid, trixie1.6-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tracsourcesarge(unfixed)medium
tracsource(unstable)0.9.5-1medium

Notes

http://trac.edgewall.org/changeset/3201
http://trac.edgewall.org/changeset/3287
the second reference fixes a regression in the first. i *believe*
that these correctly solve the problem, though we really ought
to run this by upstream or the reporter.

Search for package or bug name: Reporting problems