Unrated severityNVD Advisory· Published Jun 19, 2005· Updated Apr 16, 2026
CVE-2005-2007
CVE-2005-2007
Description
Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.
Affected products
11cpe:2.3:a:edgewall_software:trac:0.5:*:*:*:*:*:*:*+ 10 more
- cpe:2.3:a:edgewall_software:trac:0.5:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.5.1:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.5.2:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.6:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.6.1:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.7:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.7.1:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.8:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.8.1:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.8.2:*:*:*:*:*:*:*
- cpe:2.3:a:edgewall_software:trac:0.8.3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4- lists.grok.org.uk/pipermail/full-disclosure/2005-June/034618.htmlnvdPatchVendor Advisory
- secunia.com/advisories/15752nvdPatchVendor Advisory
- www.hardened-php.net/advisory-012005.phpnvdPatchVendor Advisory
- svn.edgewall.com/repos/trac/tags/trac-0.8.4/ChangeLognvd
News mentions
0No linked articles in our index yet.