Vulnerability Name: | CVE-2006-3064 (CCN-27079) | ||||||||
Assigned: | 2006-06-11 | ||||||||
Published: | 2006-06-11 | ||||||||
Updated: | 2018-10-18 | ||||||||
Summary: | SQL injection vulnerability in the add_hit function in include/function.inc.php in Coppermine Photo Gallery (CPG) 1.4.8, when "Keep detailed hit statistics" is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) referer and (2) user-agent HTTP headers. | ||||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||||
Vulnerability Type: | CWE-89 | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Sun Jun 11 2006 - 10:32:39 CDT [KAPDA::48]CopperminePhotoGallery1.4.8~ addhit() function~ SQLinjection attack Source: CCN Type: Coppermine Photo Gallery Web site Coppermine Download Maintenance Release Source: MITRE Type: CNA CVE-2006-3064 Source: MISC Type: Exploit http://myimei.com/security/2006-06-11/copperminephotogallery148-addhit-function-sqlinjection-attack.html Source: CCN Type: SA20597 Coppermine Photo Gallery SQL Injection and Clean-Up Bypass Source: SECUNIA Type: Vendor Advisory 20597 Source: CCN Type: SourceForge.net Project: Coppermine Photo Gallery: Summary Source: CCN Type: OSVDB ID: 26429 Coppermine Photo Gallery HTTP Header add_hit() Function SQL Injection Source: BUGTRAQ Type: UNKNOWN 20060611 [KAPDA::48]CopperminePhotoGallery1.4.8~ addhit() function~ SQLinjection attack Source: VUPEN Type: Vendor Advisory ADV-2006-2317 Source: XF Type: UNKNOWN coppermine-addhit-sql-injection(27079) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |