PT-2005-3079 · Edgewall · Trac

Stefan Esser

·

Published

2005-07-06

·

Updated

2008-09-05

·

CVE-2005-2147

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:P/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Trac versions prior to 0.8.4
Description: The issue allows remote attackers to read or upload arbitrary files. This can be achieved by providing a full pathname in the id parameter to either the upload or attachment viewer scripts.
Recommendations: For versions prior to 0.8.4, update to version 0.8.4 or later to resolve the issue. As a temporary workaround, consider restricting access to the upload and attachment viewer scripts until the update is applied. Avoid using the id parameter with full pathnames in the affected scripts until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-2147
DSA-739-1

Affected Products

Trac