Vulnerabilities > CVE-2006-0872 - File Include vulnerability in Coppermine Photo Gallery 1.4.3

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
PARTIAL
Availability impact
NONE
network
low complexity
coppermine
nessus

Summary

Directory traversal vulnerability in init.inc.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the lang parameter.

Vulnerable Configurations

Part Description Count
Application
Coppermine
1

Nessus

NASL familyFreeBSD Local Security Checks
NASL idFREEBSD_PKG_77CCEAEFE9A411DAB9F400123FFE8333.NASL
descriptionSecunia reports : Coppermine Photo Gallery have a vulnerability, which can be exploited by malicious people and by malicious users to compromise a vulnerable system. 1) Input passed to the
last seen2020-06-01
modified2020-06-02
plugin id21587
published2006-05-23
reporterThis script is Copyright (C) 2006-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
sourcehttps://www.tenable.com/plugins/nessus/21587
titleFreeBSD : coppermine -- File Inclusion Vulnerabilities (77cceaef-e9a4-11da-b9f4-00123ffe8333)