CVE-2008-3481

Coppermine Photo Gallery <1.4.18 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2008-3481. PoCs published by EgiX.

AI-analyzed exploit summary This exploit leverages a Local File Inclusion (LFI) vulnerability in Coppermine Photo Gallery <= 1.4.18, allowing remote code execution by manipulating the USER['lang'] cookie parameter to include arbitrary local files. The exploit includes a full interactive shell for post-exploitation.

Description

themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.

Exploits (1)

exploitdb WORKING POC VERIFIED
by EgiX · phpwebappsphp
https://www.exploit-db.com/exploits/6178

This exploit leverages a Local File Inclusion (LFI) vulnerability in Coppermine Photo Gallery <= 1.4.18, allowing remote code execution by manipulating the USER['lang'] cookie parameter to include arbitrary local files. The exploit includes a full interactive shell for post-exploitation.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Coppermine Photo Gallery <= 1.4.18
No auth needed
Prerequisites: Target must have Coppermine Photo Gallery <= 1.4.18 installed · Default charset must be set to 'utf-8' · Access to the target's web server logs for LFI
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/4108
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/6178

Scores

EPSS 0.0211
EPSS Percentile 79.4%

Details

CWE
CWE-94
Status published
Products (26)
coppermine-gallery/coppermine_photo_gallery 1.0 (2 CPE variants)
coppermine-gallery/coppermine_photo_gallery 1.1 (2 CPE variants)
coppermine-gallery/coppermine_photo_gallery 1.1.0
coppermine-gallery/coppermine_photo_gallery 1.2.0 (2 CPE variants)
coppermine-gallery/coppermine_photo_gallery 1.2.1 (3 CPE variants)
coppermine-gallery/coppermine_photo_gallery 1.3.0
coppermine-gallery/coppermine_photo_gallery 1.4 beta
coppermine-gallery/coppermine_photo_gallery 1.4.0 alpha
coppermine-gallery/coppermine_photo_gallery 1.4.1 beta
coppermine-gallery/coppermine_photo_gallery 1.4.2
... and 16 more
Published Aug 05, 2008
Tracked Since Feb 18, 2026