CVE-2005-2007: Medium severity edgewall trac vulnerability
Published Jun 19, 2005
·Updated
Directory traversal vulnerability in Edgewall Trac 0.8.3 and earlier allows remote attackers to read or write arbitrary files via a .. (dot dot) in the id parameter to the (1) upload or (2) attachment scripts.
Affected Software
11 affected components
Edgewall Software Trac=0.5
Edgewall Software Trac=0.5.1
Edgewall Software Trac=0.5.2
Edgewall Software Trac=0.6
Edgewall Software Trac=0.6.1
Edgewall Software Trac=0.7
Edgewall Software Trac=0.7.1
Edgewall Software Trac=0.8
Edgewall Software Trac=0.8.1
Edgewall Software Trac=0.8.2
Edgewall Software Trac=0.8.3
Remediation
Patch Available
Patch Available
Event History
Jun 19, 2005
CVE Published
04:00 AM
Jun 20, 2005
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-2007?
CVE-2005-2007 is considered a high severity vulnerability due to its potential for unauthorized file access.
2
How do I fix CVE-2005-2007?
To fix CVE-2005-2007, upgrade Edgewall Trac to version 0.8.4 or later.
3
What software is affected by CVE-2005-2007?
CVE-2005-2007 affects Edgewall Trac versions from 0.5.0 up to 0.8.3.
4
How does CVE-2005-2007 exploit the system?
CVE-2005-2007 exploits directory traversal by using the '..' (dot dot) notation in file path parameters.
5
Can CVE-2005-2007 lead to data breaches?
Yes, CVE-2005-2007 can lead to significant data breaches if attackers gain access to arbitrary files.