Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Trac | Edgewall_software | 0.7.1 | 0.7.1 |
Trac | Edgewall_software | 0.8.1 | 0.8.1 |
Trac | Edgewall_software | 0.8.3 | 0.8.3 |