Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.56773
Kategorie:FreeBSD Local Security Checks
Titel:FreeBSD Ports: coppermine
Zusammenfassung:The remote host is missing an update to the system; as announced in the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update to the system
as announced in the referenced advisory.

Vulnerability Insight:
The following package is affected: coppermine

CVE-2006-0872
Directory traversal vulnerability in init.inc.php in Coppermine Photo
Gallery 1.4.3 and earlier allows remote attackers to include arbitrary
files via a .. (dot dot) sequence and trailing NULL (%00) byte in the
lang parameter.

CVE-2006-0873
Absolute path traversal vulnerability in docs/showdocs.php in
Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to
include arbitrary files via the f parameter, and possibly remote files
using UNC share pathnames.

Solution:
Update your system with the appropriate patches or
software upgrades.

CVSS Score:
5.0

CVSS Vector:
AV:N/AC:L/Au:N/C:N/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2006-0872
BugTraq ID: 16718
http://www.securityfocus.com/bid/16718
Bugtraq: 20060218 Coppermine Photo Gallery <=1.4.3 remote code execution (Google Search)
http://www.securityfocus.com/archive/1/425387
http://retrogod.altervista.org/cpg_143_adv.html
http://retrogod.altervista.org/cpg_143_incl_xpl.html
http://securitytracker.com/id?1015646
http://secunia.com/advisories/18941
http://www.vupen.com/english/advisories/2006/0669
XForce ISS Database: coppermine-init-file-include(24814)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24814
Common Vulnerability Exposure (CVE) ID: CVE-2006-0873
XForce ISS Database: coppermine-showdoc-file-include(24816)
https://exchange.xforce.ibmcloud.com/vulnerabilities/24816
CopyrightCopyright (C) 2008 E-Soft Inc.

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.