PT-2006-3461 · Apache+1 · Apache+2

Published

2006-05-22

·

Updated

2017-07-20

·

CVE-2006-2514

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Coppermine galleries versions prior to 1.4.6
Description The issue allows remote attackers to upload arbitrary files by utilizing a filename with multiple file extensions, specifically when the software is running on Apache with mod mime installed.
Recommendations For versions prior to 1.4.6, update to version 1.4.6 or later to resolve the issue. As a temporary workaround, consider restricting file uploads or disabling the use of multiple file extensions in filenames until the update is applied.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2514

Affected Products

Apache
Coppermine
Mod Mime