CVE-2008-3486
06.08.2008, 17:41
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.
Vendor | Product | Version |
---|---|---|
coppermine-gallery | coppermine_photo_gallery | 𝑥 ≤ 1.4.18 |
coppermine-gallery | coppermine_photo_gallery | 1.0 |
coppermine-gallery | coppermine_photo_gallery | 1.0:rc3 |
coppermine-gallery | coppermine_photo_gallery | 1.1 |
coppermine-gallery | coppermine_photo_gallery | 1.1:beta_2 |
coppermine-gallery | coppermine_photo_gallery | 1.1.0 |
coppermine-gallery | coppermine_photo_gallery | 1.2.0 |
coppermine-gallery | coppermine_photo_gallery | 1.2.0:rc2 |
coppermine-gallery | coppermine_photo_gallery | 1.2.1 |
coppermine-gallery | coppermine_photo_gallery | 1.2.1:b |
coppermine-gallery | coppermine_photo_gallery | 1.2.1:b-nuke |
coppermine-gallery | coppermine_photo_gallery | 1.3.0 |
coppermine-gallery | coppermine_photo_gallery | 1.4:beta |
coppermine-gallery | coppermine_photo_gallery | 1.4.0:alpha |
coppermine-gallery | coppermine_photo_gallery | 1.4.1:beta |
coppermine-gallery | coppermine_photo_gallery | 1.4.2 |
coppermine-gallery | coppermine_photo_gallery | 1.4.3 |
coppermine-gallery | coppermine_photo_gallery | 1.4.4 |
coppermine-gallery | coppermine_photo_gallery | 1.4.5 |
coppermine-gallery | coppermine_photo_gallery | 1.4.6 |
coppermine-gallery | coppermine_photo_gallery | 1.4.7 |
coppermine-gallery | coppermine_photo_gallery | 1.4.8 |
coppermine-gallery | coppermine_photo_gallery | 1.4.9 |
coppermine-gallery | coppermine_photo_gallery | 1.4.10 |
coppermine-gallery | coppermine_photo_gallery | 1.4.11 |
coppermine-gallery | coppermine_photo_gallery | 1.4.12 |
coppermine-gallery | coppermine_photo_gallery | 1.4.13 |
coppermine-gallery | coppermine_photo_gallery | 1.4.14 |
coppermine-gallery | coppermine_photo_gallery | 1.4.15 |
coppermine-gallery | coppermine_photo_gallery | 1.4.16 |
coppermine-gallery | coppermine_photo_gallery | 1.4.17 |
𝑥
= Vulnerable software versions
References