PT-2007-2535 · Coppermine · Coppermine Photo Gallery

Rst/Ghc

·

Publicado

2007-02-26

·

Atualizado

2018-10-16

·

CVE-2007-1107

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Coppermine Photo Gallery versions 1.3.x through 1.4.x
Description The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved via a cpg131 fav cookie in the thumbnails.php file. The estimated number of potentially affected devices and details about real-world incidents are not specified.
Recommendations For Coppermine Photo Gallery versions 1.3.x through 1.4.x, consider restricting access to the thumbnails.php file until a fix is available. As a temporary workaround, avoid using the cpg131 fav cookie in the affected API endpoint.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1107

Produtos afetados

Coppermine Photo Gallery