Risk: Medium
Trac is an enhanced wiki and issue tracking system for software development projects. Edgewall, the vendor of Trac, has recently discovered that it is susceptible to cross site scripting attacks when viewing pages in Internet Explorer and Opera. Other browsers may also be affected but as yet, are unconfirmed.
This vulnerability enables hackers to insert code to steal cookies, redirect users to sites of their choice, request confirmation of bank account details or other malicious attacks.
To resolve the potential problem, update to version 0.9.3 at http://projects.edgewall.com/trac/wiki/TracDownload