Unrated severityNVD Advisory· Published Apr 20, 2006· Updated Apr 16, 2026
CVE-2006-1909
CVE-2006-1909
Description
Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.
Affected products
1- cpe:2.3:a:coppermine:coppermine_photo_gallery:1.4.4:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- www.securityfocus.com/bid/17570nvdExploit
- myimei.com/security/2006-04-14/copperminephotogallery144-plugininclusionsystemindexphp-remotefileinclusion-attack.htmlnvd
- secunia.com/advisories/19665nvd
- www.securityfocus.com/archive/1/431062nvd
- www.securityfocus.com/archive/1/431118/30/0/threadednvd
- www.vupen.com/english/advisories/2006/1392nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/25866nvd
News mentions
0No linked articles in our index yet.