PT-2007-5474 · Coppermine · Coppermine Photo Gallery

Published

2007-08-09

·

Updated

2018-10-15

·

CVE-2007-4283

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Coppermine Photo Gallery version 1.3.1
Description The issue allows remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter in the bridge/yabbse.inc.php file.
Recommendations For version 1.3.1, update to a newer version that contains a fix for this issue. As a temporary workaround, consider restricting access to the bridge/yabbse.inc.php file or avoiding the use of the sourcedir parameter in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-4283

Affected Products

Coppermine Photo Gallery