First published: Wed Aug 06 2008(Updated: )
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Coppermine-gallery Coppermine Photo Gallery | =1.4.17 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.11 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.14 | |
Coppermine-gallery Coppermine Photo Gallery | =1.2.0-rc2 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.8 | |
Coppermine-gallery Coppermine Photo Gallery | =1.2.1 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.7 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.0-alpha | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.2 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.16 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.3 | |
Coppermine-gallery Coppermine Photo Gallery | =1.2.1-b | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.15 | |
Coppermine-gallery Coppermine Photo Gallery | =1.0-rc3 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.5 | |
Coppermine-gallery Coppermine Photo Gallery | =1.1 | |
Coppermine-gallery Coppermine Photo Gallery | =1.2.0 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.4 | |
Coppermine-gallery Coppermine Photo Gallery | =1.2.1-b-nuke | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.9 | |
Coppermine-gallery Coppermine Photo Gallery | <=1.4.18 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.12 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.13 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.10 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.6 | |
Coppermine-gallery Coppermine Photo Gallery | =1.3.0 | |
Coppermine-gallery Coppermine Photo Gallery | =1.1.0 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4.1-beta | |
Coppermine-gallery Coppermine Photo Gallery | =1.0 | |
Coppermine-gallery Coppermine Photo Gallery | =1.4-beta | |
Coppermine-gallery Coppermine Photo Gallery | =1.1-beta_2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.