PT-2007-2535 · Coppermine · Coppermine Photo Gallery

Rst/Ghc

·

Published

2007-02-26

·

Updated

2018-10-16

·

CVE-2007-1107

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Coppermine Photo Gallery versions 1.3.x through 1.4.x
Description The issue allows remote authenticated users to execute arbitrary SQL commands. This is achieved via a cpg131 fav cookie in the thumbnails.php file. The estimated number of potentially affected devices and details about real-world incidents are not specified.
Recommendations For Coppermine Photo Gallery versions 1.3.x through 1.4.x, consider restricting access to the thumbnails.php file until a fix is available. As a temporary workaround, avoid using the cpg131 fav cookie in the affected API endpoint.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1107

Affected Products

Coppermine Photo Gallery