CVE-2012-1614
Coppermine Photo Gallery < 1.5.20 - Exposure of Sensitive Information via Error Message
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-1614. PoCs published by waraxe.
AI-analyzed exploit summary This is a detailed advisory describing multiple vulnerabilities in Coppermine 1.5.18, including stored XSS and path disclosure issues. It provides step-by-step testing instructions but does not include executable exploit code.
Description
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than parameter to search.inc.php, which reveals the installation path in an error message.
Exploits (1)
This is a detailed advisory describing multiple vulnerabilities in Coppermine 1.5.18, including stored XSS and path disclosure issues. It provides step-by-step testing instructions but does not include executable exploit code.