CVE-2008-3486

Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
coppermine-gallerycoppermine_photo_gallery
𝑥
≤ 1.4.18
coppermine-gallerycoppermine_photo_gallery
1.0
coppermine-gallerycoppermine_photo_gallery
1.0:rc3
coppermine-gallerycoppermine_photo_gallery
1.1
coppermine-gallerycoppermine_photo_gallery
1.1:beta_2
coppermine-gallerycoppermine_photo_gallery
1.1.0
coppermine-gallerycoppermine_photo_gallery
1.2.0
coppermine-gallerycoppermine_photo_gallery
1.2.0:rc2
coppermine-gallerycoppermine_photo_gallery
1.2.1
coppermine-gallerycoppermine_photo_gallery
1.2.1:b
coppermine-gallerycoppermine_photo_gallery
1.2.1:b-nuke
coppermine-gallerycoppermine_photo_gallery
1.3.0
coppermine-gallerycoppermine_photo_gallery
1.4:beta
coppermine-gallerycoppermine_photo_gallery
1.4.0:alpha
coppermine-gallerycoppermine_photo_gallery
1.4.1:beta
coppermine-gallerycoppermine_photo_gallery
1.4.2
coppermine-gallerycoppermine_photo_gallery
1.4.3
coppermine-gallerycoppermine_photo_gallery
1.4.4
coppermine-gallerycoppermine_photo_gallery
1.4.5
coppermine-gallerycoppermine_photo_gallery
1.4.6
coppermine-gallerycoppermine_photo_gallery
1.4.7
coppermine-gallerycoppermine_photo_gallery
1.4.8
coppermine-gallerycoppermine_photo_gallery
1.4.9
coppermine-gallerycoppermine_photo_gallery
1.4.10
coppermine-gallerycoppermine_photo_gallery
1.4.11
coppermine-gallerycoppermine_photo_gallery
1.4.12
coppermine-gallerycoppermine_photo_gallery
1.4.13
coppermine-gallerycoppermine_photo_gallery
1.4.14
coppermine-gallerycoppermine_photo_gallery
1.4.15
coppermine-gallerycoppermine_photo_gallery
1.4.16
coppermine-gallerycoppermine_photo_gallery
1.4.17
𝑥
= Vulnerable software versions