Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Coppermine_photo_gallery | Coppermine | * | 1.4.5 (including) |
Coppermine_photo_gallery | Coppermine | 1.0_rc3 (including) | 1.0_rc3 (including) |
Coppermine_photo_gallery | Coppermine | 1.1.0 (including) | 1.1.0 (including) |
Coppermine_photo_gallery | Coppermine | 1.1_beta_2 (including) | 1.1_beta_2 (including) |
Coppermine_photo_gallery | Coppermine | 1.2 (including) | 1.2 (including) |
Coppermine_photo_gallery | Coppermine | 1.2.1 (including) | 1.2.1 (including) |
Coppermine_photo_gallery | Coppermine | 1.2.2_b (including) | 1.2.2_b (including) |
Coppermine_photo_gallery | Coppermine | 1.3 (including) | 1.3 (including) |
Coppermine_photo_gallery | Coppermine | 1.3.2 (including) | 1.3.2 (including) |
Coppermine_photo_gallery | Coppermine | 1.3.3 (including) | 1.3.3 (including) |
Coppermine_photo_gallery | Coppermine | 1.4.2 (including) | 1.4.2 (including) |
Coppermine_photo_gallery | Coppermine | 1.4.3 (including) | 1.4.3 (including) |
Coppermine_photo_gallery | Coppermine | 1.4.4 (including) | 1.4.4 (including) |
Coppermine_photo_gallery | Coppermine | 1.4_beta (including) | 1.4_beta (including) |