Show filters
26 Total Results
Displaying 11-20 of 26
Sort by:
Attacker Value
Unknown
CVE-2008-1841
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in the session handling functionality in bridge/coppermine.inc.php in Coppermine Photo Gallery (CPG) 1.4.17 and earlier allows remote attackers to execute arbitrary SQL commands via an input field associated with the session_id variable, as exploited in the wild in April 2008. NOTE: the fix for CVE-2008-1840 was intended to address this vulnerability, but is actually inapplicable.
0
Attacker Value
Unknown
CVE-2008-1840
Disclosure Date: April 16, 2008 (last updated October 04, 2023)
SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload.
0
Attacker Value
Unknown
CVE-2007-4977
Disclosure Date: September 19, 2007 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the referer parameter.
0
Attacker Value
Unknown
CVE-2007-4976
Disclosure Date: September 19, 2007 (last updated October 04, 2023)
Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and earlier allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.
0
Attacker Value
Unknown
CVE-2007-2715
Disclosure Date: May 16, 2007 (last updated October 04, 2023)
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1) username, or the (2) password and password2 parameters in an edit action.
0
Attacker Value
Unknown
CVE-2007-0122
Disclosure Date: January 09, 2007 (last updated October 04, 2023)
Multiple SQL injection vulnerabilities in Coppermine Photo Gallery 1.4.10 and earlier allow remote authenticated administrators to execute arbitrary SQL commands via (1) the cat parameter to albmgr.php, and possibly (2) the gid parameter to usermgr.php; (3) the start parameter to db_ecard.php; and the albumid parameter to unspecified files, related to the (4) filename_to_title and (5) del_titles functions.
0
Attacker Value
Unknown
CVE-2006-4030
Disclosure Date: August 16, 2006 (last updated October 04, 2023)
Unspecified vulnerability in the stats module in Gallery 1.5.1-RC2 and earlier allows remote attackers to obtain sensitive information via unspecified attack vectors, related to "two file exposure bugs."
0
Attacker Value
Unknown
CVE-2006-2976
Disclosure Date: June 12, 2006 (last updated October 04, 2023)
Unspecified vulnerability in usermgr.php in Coppermine Photo Gallery before 1.4.7 has unknown impact and remote attack vectors, possibly related to authorization/authentication errors.
0
Attacker Value
Unknown
CVE-2006-2514
Disclosure Date: May 22, 2006 (last updated October 04, 2023)
Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arbitrary files via a filename with multiple file extensions.
0
Attacker Value
Unknown
CVE-2006-1909
Disclosure Date: April 20, 2006 (last updated October 04, 2023)
Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.
0