Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to write arbitrary files via ".." sequences in file attachments.
| Software | From | Fixed in |
|---|---|---|
| apple / mac_os_x_server | 10.5.2 | 10.5.2.x |
| apple / mac_os_x | 10.5.2 | 10.5.2.x |