CVE-2007-4976
Coppermine Photo Gallery - Authenticated Path Traversal via viewlog.php log Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2007-4976. PoCs published by L4teral.
AI-analyzed exploit summary The exploit demonstrates a local file inclusion (LFI) vulnerability in Coppermine Photo Gallery, allowing attackers to read arbitrary files (e.g., /etc/passwd) via path traversal. The PoC is a simple URL-based attack with no additional payload.
Description
Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.
Exploits (1)
The exploit demonstrates a local file inclusion (LFI) vulnerability in Coppermine Photo Gallery, allowing attackers to read arbitrary files (e.g., /etc/passwd) via path traversal. The PoC is a simple URL-based attack with no additional payload.