PT-2005-3079 · Edgewall · Trac
Stefan Esser
·
Published
2005-07-06
·
Updated
2008-09-05
·
CVE-2005-2147
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions:
Trac versions prior to 0.8.4
Description:
The issue allows remote attackers to read or upload arbitrary files. This can be achieved by providing a full pathname in the
id parameter to either the upload or attachment viewer scripts.Recommendations:
For versions prior to 0.8.4, update to version 0.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the upload and attachment viewer scripts until the update is applied. Avoid using the
id parameter with full pathnames in the affected scripts until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trac