>> Coppermine Photo Gallery "file" Parameter Local File Inclusion Vulnerability
Title : Coppermine Photo Gallery "file" Parameter Local File Inclusion Vulnerability VUPEN ID : VUPEN/ADV-2006-1392 CVE ID : CVE-2006-1909
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-04-18
Technical Description
A vulnerability has been identified in Coppermine Photo Gallery, which could be exploited by remote attackers to gain knowledge of sensitive information. This flaw is due to input validation errors in the "cpg/index.php" script that does not properly validate the "file" parameter, which could be exploited by remote attackers to include local files with the privileges of the web server.