PT-2004-2885 · Coppermine · Coppermine Photo Gallery

Janek Vind

+1

·

Publicado

2004-04-30

·

Atualizado

2017-07-11

·

CVE-2004-1989

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Coppermine Photo Gallery version 1.2.2b
Description The issue allows remote attackers to execute arbitrary PHP code by modifying the THEME DIR parameter to reference a URL on a remote web server that contains user list info box.inc.
Recommendations For Coppermine Photo Gallery version 1.2.2b, avoid using the THEME DIR parameter to reference remote URLs until a fix is available. Consider restricting access to the theme.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1989

Produtos afetados

Coppermine Photo Gallery