PT-2005-3079 · Edgewall · Trac

Stefan Esser

·

Publicado

2005-07-06

·

Atualizado

2008-09-05

·

CVE-2005-2147

CVSS v2.0

6.4

Média

VetorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Trac versions prior to 0.8.4
Description: The issue allows remote attackers to read or upload arbitrary files. This can be achieved by providing a full pathname in the id parameter to either the upload or attachment viewer scripts.
Recommendations: For versions prior to 0.8.4, update to version 0.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the upload and attachment viewer scripts until the update is applied. Avoid using the id parameter with full pathnames in the affected scripts until the issue is resolved.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2147
DSA-739-1

Produtos afetados

Trac