Back
CVE-2005-2007
Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.
Published: Jun 19, 2005
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (11)
| Vendor | Product | Version |
|---|---|---|
| edgewall_software | trac | 0.5 |
| edgewall_software | trac | 0.5.1 |
| edgewall_software | trac | 0.5.2 |
| edgewall_software | trac | 0.6 |
| edgewall_software | trac | 0.6.1 |
| edgewall_software | trac | 0.7 |
| edgewall_software | trac | 0.7.1 |
| edgewall_software | trac | 0.8 |
| edgewall_software | trac | 0.8.1 |
| edgewall_software | trac | 0.8.2 |
| edgewall_software | trac | 0.8.3 |
GitHub Security Advisory GHSA-p2r2-593v-fg6q
Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to...
References (8)
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034618.html Patch, Vendor Advisory
- http://secunia.com/advisories/15752 Patch, Vendor Advisory
- http://svn.edgewall.com/repos/trac/tags/trac-0.8.4/ChangeLog
- http://www.hardened-php.net/advisory-012005.php Patch, Vendor Advisory
- http://lists.grok.org.uk/pipermail/full-disclosure/2005-June/034618.html Patch, Vendor Advisory
- http://secunia.com/advisories/15752 Patch, Vendor Advisory
- http://svn.edgewall.com/repos/trac/tags/trac-0.8.4/ChangeLog
- http://www.hardened-php.net/advisory-012005.php Patch, Vendor Advisory
Risk Scores
CVSS Score
6.4 / 10
EPSS Score
1.79%
Top 23% most likely to be exploited
Threat Score
26.1 / 100
Data Sources
NVD
EPSS
GitHub