Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Trac | Edgewall_software | 0.5 (including) | 0.5 (including) |
| Trac | Edgewall_software | 0.5.1 (including) | 0.5.1 (including) |
| Trac | Edgewall_software | 0.5.2 (including) | 0.5.2 (including) |
| Trac | Edgewall_software | 0.6 (including) | 0.6 (including) |
| Trac | Edgewall_software | 0.6.1 (including) | 0.6.1 (including) |
| Trac | Edgewall_software | 0.7 (including) | 0.7 (including) |
| Trac | Edgewall_software | 0.7.1 (including) | 0.7.1 (including) |
| Trac | Edgewall_software | 0.8 (including) | 0.8 (including) |
| Trac | Edgewall_software | 0.8.1 (including) | 0.8.1 (including) |
| Trac | Edgewall_software | 0.8.2 (including) | 0.8.2 (including) |
| Trac | Edgewall_software | 0.8.3 (including) | 0.8.3 (including) |