← Back

CVE-2008-3486

nvd nist
Published: Aug 6, 2008Modified: Apr 23, 2026

JSON object

Loading...
7.5
Vector
AV:N/AC:L/Au:N/C:P/I:P/A:P
Exploitability: 10.0 / Impact: 6.4
Source: NVD

Description

Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.

Affected (31)

Coppermine Photo Gallery
Configuration A
31 vulnerable
Vulnerable SoftwareAffected Versions
Coppermine Gallery
Up to 1.4.18
Version 1.0
Version 1.0 rc3
Version 1.1.0
Version 1.1
Version 1.1 beta_2
Version 1.2.0
Version 1.2.0 rc2
Version 1.2.1
Version 1.2.1 b-nuke
Version 1.2.1 b
Version 1.3.0
Version 1.4.0 alpha
Version 1.4.10
Version 1.4.11
Version 1.4.12
Version 1.4.13
Version 1.4.14
Version 1.4.15
Version 1.4.16
Version 1.4.17
Version 1.4.1 beta
Version 1.4.2
Version 1.4.3
Version 1.4.4
Version 1.4.5
Version 1.4.6
Version 1.4.7
Version 1.4.8
Version 1.4.9
Version 1.4 beta

References (10)

Source: cve@mitre.org
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.