PT-2005-3079 · Edgewall · Trac
Stefan Esser
·
Publicado
2005-07-06
·
Atualizado
2008-09-05
·
CVE-2005-2147
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Trac versions prior to 0.8.4
Description:
The issue allows remote attackers to read or upload arbitrary files. This can be achieved by providing a full pathname in the
id parameter to either the upload or attachment viewer scripts.Recommendations:
For versions prior to 0.8.4, update to version 0.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the upload and attachment viewer scripts until the update is applied. Avoid using the
id parameter with full pathnames in the affected scripts until the issue is resolved.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Trac