CVE-2008-1841

EXPLOITED IN THE WILD

Coppermine Photo Gallery <1.4.17 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2008-1841 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io).

Description

SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix for CVE-2008-1840 was intended to address this vulnerability, but is actually inapplicable.

Scores

EPSS 0.0186
EPSS Percentile 77.1%

Details

VulnCheck KEV 2008-04-16
InTheWild.io 2017-08-08
CWE
CWE-89
Status published
Products (22)
coppermine/coppermine_photo_gallery 1.2.0
coppermine/coppermine_photo_gallery 1.2.0rc2
coppermine/coppermine_photo_gallery 1.2.1
coppermine/coppermine_photo_gallery 1.3.0
coppermine/coppermine_photo_gallery 1.3.1
coppermine/coppermine_photo_gallery 1.3.2
coppermine/coppermine_photo_gallery 1.3.3
coppermine/coppermine_photo_gallery 1.3.5
coppermine/coppermine_photo_gallery 1.4.2
coppermine/coppermine_photo_gallery 1.4.4
... and 12 more
Published Apr 16, 2008
Tracked Since Feb 18, 2026