Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Trac | Edgewall_software | 0.5 (including) | 0.5 (including) |
Trac | Edgewall_software | 0.5.1 (including) | 0.5.1 (including) |
Trac | Edgewall_software | 0.5.2 (including) | 0.5.2 (including) |
Trac | Edgewall_software | 0.6 (including) | 0.6 (including) |
Trac | Edgewall_software | 0.6.1 (including) | 0.6.1 (including) |
Trac | Edgewall_software | 0.7 (including) | 0.7 (including) |
Trac | Edgewall_software | 0.7.1 (including) | 0.7.1 (including) |
Trac | Edgewall_software | 0.8 (including) | 0.8 (including) |
Trac | Edgewall_software | 0.8.1 (including) | 0.8.1 (including) |
Trac | Edgewall_software | 0.8.2 (including) | 0.8.2 (including) |
Trac | Edgewall_software | 0.8.3 (including) | 0.8.3 (including) |