{"id":"CVE-2005-2147","details":"Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.","modified":"2026-04-10T03:38:08.754564Z","published":"2005-07-06T04:00:00Z","references":[{"type":"ADVISORY","url":"http://secunia.com/advisories/15752"},{"type":"ADVISORY","url":"http://www.debian.org/security/2005/dsa-739"},{"type":"ADVISORY","url":"http://www.hardened-php.net/advisory-012005.php"},{"type":"FIX","url":"http://secunia.com/advisories/15752"},{"type":"FIX","url":"http://www.hardened-php.net/advisory-012005.php"},{"type":"FIX","url":"http://www.securityfocus.com/bid/13990"}],"schema_version":"1.7.5"}