CVE-2008-3486: Path Traversal
Directory traversal vulnerability in the usergetprofile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an data cookie.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-3486?
CVE-2008-3486 has a high severity level due to its potential for remote code execution.
How do I fix CVE-2008-3486?
To fix CVE-2008-3486, upgrade to Coppermine Photo Gallery version 1.4.19 or later.
What systems are affected by CVE-2008-3486?
CVE-2008-3486 affects all versions of Coppermine Photo Gallery up to and including 1.4.18.
What type of vulnerability is CVE-2008-3486?
CVE-2008-3486 is a directory traversal vulnerability that allows attackers to include arbitrary local files.
Can CVE-2008-3486 lead to data compromise?
Yes, exploitation of CVE-2008-3486 can lead to unauthorized access to sensitive local files.