First published: Fri Feb 24 2006(Updated: )
Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Coppermine Coppermine Photo Gallery | =1.4.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0873 is considered a high-severity vulnerability due to its potential to allow remote file inclusion.
To fix CVE-2006-0873, upgrade Coppermine Photo Gallery to version 1.4.4 or later, which addresses this vulnerability.
The impact of CVE-2006-0873 includes unauthorized access to sensitive files on the server and possible execution of arbitrary code.
CVE-2006-0873 affects users of Coppermine Photo Gallery versions 1.4.3 and earlier.
Attackers can exploit CVE-2006-0873 by manipulating the 'f' parameter in requests to include arbitrary files on the server.