coppermine-gallery.netConfirmation
http://coppermine-gallery.net/forum/index.php?topic=50103.0 CVE-2008-0504
Coppermine Photo Gallery 1.4.10 - 'cpg1410_xek.php' SQL Injection
Record summary
CVE-2008-0504 has a selected CVSS score of 6.5; EIP currently links 1 catalogued exploit.
Description
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) before 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBCoppermine Photo Gallery 1.4.10 - 'cpg1410_xek.php' SQL InjectionExploitDB exploitby bazikNot analyzed1 file
References
828682Third-party advisory
http://secunia.com/advisories/28682 20080131 [waraxe-2008-SA#066] - Multiple Vulnerabilities in Coppermine 1.4.14mailing list
http://www.securityfocus.com/archive/1/487351/100/200/threaded 27509vdb entry
http://www.securityfocus.com/bid/27509 1019285vdb entry
http://www.securitytracker.com/id?1019285 ADV-2008-0367vdb entry
http://www.vupen.com/english/advisories/2008/0367 waraxe.us
http://www.waraxe.us/advisory-66.html nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-0504