← All CVEs

CVE-2004-1986

medium · 5

Directory traversal vulnerability in modules.php in Coppermine Photo Gallery 1.2.2b and 1.2.0 RC4 allows remote attackers with administrative privileges to read arbitrary files via a .. (dot dot) in the startdir parameter.

5
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2004-04-04
Published

AV:N/AC:L/Au:N/C:P/I:N/A:N

Affected products

VendorProductAffected versions
copperminecoppermine_photo_gallery1.0_rc3
copperminecoppermine_photo_gallery1.1_.0
copperminecoppermine_photo_gallery1.1_beta_2
copperminecoppermine_photo_gallery1.2
copperminecoppermine_photo_gallery1.2.1
copperminecoppermine_photo_gallery1.2.2_b
francisco_burziphp-nuke6.9
francisco_burziphp-nuke7.0
francisco_burziphp-nuke7.0_final
francisco_burziphp-nuke7.1
francisco_burziphp-nuke7.2

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2004-1986