Show filters
26 Total Results
Displaying 1-10 of 26
Sort by:
Attacker Value
Unknown
CVE-2012-1614
Disclosure Date: September 04, 2012 (last updated October 05, 2023)
Coppermine Photo Gallery before 1.5.20 allows remote attackers to obtain sensitive information via (1) a direct request to plugins/visiblehookpoints/index.php, an invalid (2) page or (3) cat parameter to thumbnails.php, an invalid (4) page parameter to usermgr.php, or an invalid (5) newer_than or (6) older_than parameter to search.inc.php, which reveals the installation path in an error message.
0
Attacker Value
Unknown
CVE-2012-1613
Disclosure Date: September 04, 2012 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in edit_one_pic.php in Coppermine Photo Gallery before 1.5.20 allows remote authenticated users with certain privileges to inject arbitrary web script or HTML via the keywords parameter.
0
Attacker Value
Unknown
CVE-2010-4667
Disclosure Date: June 14, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.4.27 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2011-2476
Disclosure Date: June 14, 2011 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Coppermine Photo Gallery (CPG) before 1.5.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2010-4667.
0
Attacker Value
Unknown
CVE-2010-4693
Disclosure Date: January 11, 2011 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in Coppermine Photo Gallery 1.5.10 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) h and (2) t parameters to help.php, or (3) picfile_XXX parameter to searchnew.php.
0
Attacker Value
Unknown
CVE-2008-7186
Disclosure Date: September 09, 2009 (last updated October 04, 2023)
Coppermine Photo Gallery (CPG) 1.4.14 does not restrict access to update.php, which allows remote attackers to obtain sensitive information such as the database table prefix via a direct request. NOTE: this might be leveraged for attacks against CVE-2008-0504.
0
Attacker Value
Unknown
CVE-2008-7187
Disclosure Date: September 09, 2009 (last updated October 04, 2023)
Coppermine Photo Gallery (CPG) 1.4.14 allows remote attackers to obtain sensitive information via a direct request to include/slideshow.inc.php, which leaks the installation path in an error message.
0
Attacker Value
Unknown
CVE-2009-1616
Disclosure Date: May 11, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in docs/showdoc.php in Coppermine Photo Gallery (CPG) before 1.4.22 allows remote attackers to inject arbitrary web script or HTML via the css parameter, a different vector than CVE-2008-0505.
0
Attacker Value
Unknown
CVE-2008-3486
Disclosure Date: August 06, 2008 (last updated October 04, 2023)
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier, when the charset is utf-8, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the lang part of serialized data in an _data cookie.
0
Attacker Value
Unknown
CVE-2008-3481
Disclosure Date: August 05, 2008 (last updated October 04, 2023)
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in an error message.
0