PT-2005-2238 · Coppermine · Coppermine Photo Gallery

Janek Vind

+1

·

Published

2005-04-22

·

Updated

2017-07-11

·

CVE-2005-1225

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Coppermine Photo Gallery version 1.3.2
Description The issue allows remote attackers to execute arbitrary SQL commands. This can be achieved via the favs parameter to (1) 'init.inc.php' or (2) 'zipdownload.php' API endpoints.
Recommendations For Coppermine Photo Gallery version 1.3.2, consider restricting access to the favs parameter in the affected API endpoints until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-1225

Affected Products

Coppermine Photo Gallery