CVE-2006-2106: XSS
Published Apr 29, 2006
·Updated
Cross-site scripting (XSS) vulnerability in Edgewall Software Trac 0.9.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors related to a "wiki macro."
Affected Software
1 affected component
Edgewall Software Trac=0.9.4
Remediation
Patch Available
Patch Available
Event History
Apr 29, 2006
CVE Published
10:02 AM
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-2106?
CVE-2006-2106 is considered a cross-site scripting (XSS) vulnerability that poses a medium risk due to potential impact on user data and site integrity.
2
How do I fix CVE-2006-2106?
To fix CVE-2006-2106, upgrade to Trac version 0.9.5 or later which addresses the XSS vulnerability.
3
What software is affected by CVE-2006-2106?
CVE-2006-2106 affects Edgewall Software Trac version 0.9.4 and earlier.
4
What kind of attack does CVE-2006-2106 allow?
CVE-2006-2106 allows remote attackers to inject arbitrary web script or HTML via a vulnerable wiki macro.
5
Is CVE-2006-2106 easy to exploit?
Exploiting CVE-2006-2106 can be relatively easy for attackers familiar with how to manipulate web scripts.