CVE-2006-1909: Medium severity Coppermine Coppermine Photo Gallery vulnerability
Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1909?
CVE-2006-1909 is classified as a medium severity vulnerability due to its potential to expose sensitive files.
How do I fix CVE-2006-1909?
To fix CVE-2006-1909, upgrade to Coppermine version 1.4.5 or later, which addresses this vulnerability.
What type of vulnerability is CVE-2006-1909?
CVE-2006-1909 is a directory traversal vulnerability allowing unauthorized file access.
Which software versions are affected by CVE-2006-1909?
CVE-2006-1909 specifically affects Coppermine Photo Gallery version 1.4.4.
Can CVE-2006-1909 lead to complete server compromise?
While CVE-2006-1909 may allow an attacker to read arbitrary files, it does not directly compromise the server itself.