CVE-2006-0872: Medium severity Coppermine Coppermine Photo Gallery vulnerability
Published Feb 24, 2006
·Updated
Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter.
Affected Software
1 affected component
Coppermine Coppermine Photo Gallery=1.4.3
Remediation
Patch Available
Event History
Feb 24, 2006
CVE Published
11:02 AM
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0872?
CVE-2006-0872 has a high severity rating due to the potential for remote file inclusion attacks.
2
How do I fix CVE-2006-0872?
To fix CVE-2006-0872, upgrade Coppermine Photo Gallery to version 1.4.4 or later.
3
What platforms are affected by CVE-2006-0872?
CVE-2006-0872 affects Coppermine Photo Gallery version 1.4.3 and earlier.
4
Can CVE-2006-0872 be exploited remotely?
Yes, CVE-2006-0872 can be exploited remotely by attackers to include arbitrary files.
5
What is the main cause of CVE-2006-0872?
The main cause of CVE-2006-0872 is a directory traversal vulnerability allowing the use of .. sequences in file inclusion.