Absolute path traversal vulnerability in docs/showdocs.php in Coppermine Photo Gallery 1.4.3 and earlier allows remote attackers to include arbitrary files via the f parameter, and possibly remote files using UNC share pathnames.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coppermine_photo_gallery | Coppermine | 1.4.3 (including) | 1.4.3 (including) |