4.3
CVE-2005-4644
- EPSS 1.48%
- Veröffentlicht 31.12.2005 05:00:00
- Zuletzt bearbeitet 16.06.2026 22:19:10
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in the HTML WikiProcessor in Edgewall Trac 0.9.2 allows remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Edgewall Software ≫ Trac Version0.9.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.48% | 0.704 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/18555
http://www.debian.org/security/2006/dsa-951
http://projects.edgewall.com/trac/ticket/2473
http://secunia.com/advisories/18465
http://trac.edgewall.org/ticket/2473
http://www.securityfocus.com/bid/16198
http://www.vupen.com/english/advisories/2006/0226
https://exchange.xforce.ibmcloud.com/vulnerabilities/24183