First published: Fri Feb 24 2006(Updated: )
Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Coppermine Coppermine Photo Gallery | =1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0872 has a high severity rating due to the potential for remote file inclusion attacks.
To fix CVE-2006-0872, upgrade Coppermine Photo Gallery to version 1.4.4 or later.
CVE-2006-0872 affects Coppermine Photo Gallery version 1.4.3 and earlier.
Yes, CVE-2006-0872 can be exploited remotely by attackers to include arbitrary files.
The main cause of CVE-2006-0872 is a directory traversal vulnerability allowing the use of .. sequences in file inclusion.