First published: Thu Apr 20 2006(Updated: )
Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Coppermine Coppermine Photo Gallery | =1.4.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1909 is classified as a medium severity vulnerability due to its potential to expose sensitive files.
To fix CVE-2006-1909, upgrade to Coppermine version 1.4.5 or later, which addresses this vulnerability.
CVE-2006-1909 is a directory traversal vulnerability allowing unauthorized file access.
CVE-2006-1909 specifically affects Coppermine Photo Gallery version 1.4.4.
While CVE-2006-1909 may allow an attacker to read arbitrary files, it does not directly compromise the server itself.