CVE-2007-1405

NameCVE-2007-1405
DescriptionCross-site scripting (XSS) vulnerability in the "download wiki page as text" feature in Trac before 0.10.3.1, when Microsoft Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs414134, 420219

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
trac (PTS)buster1.2.3+dfsg-1fixed
sid, trixie1.6-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tracsourceetch0.10.3-1etch1
tracsource(unstable)0.10.4-1414134, 420219

Notes

Browser bug, only exploitable on IE, still fixed in a point release

Search for package or bug name: Reporting problems