PT-2004-2885 · Coppermine · Coppermine Photo Gallery

Janek Vind

+1

·

Published

2004-04-30

·

Updated

2017-07-11

·

CVE-2004-1989

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Coppermine Photo Gallery version 1.2.2b
Description The issue allows remote attackers to execute arbitrary PHP code by modifying the THEME DIR parameter to reference a URL on a remote web server that contains user list info box.inc.
Recommendations For Coppermine Photo Gallery version 1.2.2b, avoid using the THEME DIR parameter to reference remote URLs until a fix is available. Consider restricting access to the theme.php file to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1989

Affected Products

Coppermine Photo Gallery