6.4
CVSSv2

CVE-2005-2147

Published: 06/07/2005 Updated: 05/09/2008
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

Trac prior to 0.8.4 allows remote malicious users to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.

Vulnerable Product Search on Vulmon Subscribe to Product

edgewall software trac 0.7.1

edgewall software trac 0.8.1

edgewall software trac 0.8.3