PT-2006-3461 · Apache+1 · Apache+2
Published
2006-05-22
·
Updated
2017-07-20
·
CVE-2006-2514
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Coppermine galleries versions prior to 1.4.6
Description
The issue allows remote attackers to upload arbitrary files by utilizing a filename with multiple file extensions, specifically when the software is running on Apache with mod mime installed.
Recommendations
For versions prior to 1.4.6, update to version 1.4.6 or later to resolve the issue. As a temporary workaround, consider restricting file uploads or disabling the use of multiple file extensions in filenames until the update is applied.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache
Coppermine
Mod Mime