Vulnerability Name: | CVE-2006-5622 (CCN-29851) | ||||||||
Assigned: | 2006-10-27 | ||||||||
Published: | 2006-10-27 | ||||||||
Updated: | 2017-10-19 | ||||||||
Summary: | SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter. This vulnerability is addressed in the following product release: Coppermine, Photo Gallery, 1.4.10 | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P) 7.1 High (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P/E:H/RL:U/RC:UR)
6.2 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: Full-Disclosure Mailing List, Fri Oct 27 2006 - 14:09:01 CDT Coppermine 1.4.9 SQL injection Source: CCN Type: Coppermine Photo Gallery Web site Coppermine Download Maintenance Release Source: CONFIRM Type: Patch http://coppermine-gallery.net/forum/index.php?topic=37895.0 Source: MITRE Type: CNA CVE-2006-5622 Source: CCN Type: SA22625 Coppermine Photo Gallery "aid" SQL Injection Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 22625 Source: CCN Type: OSVDB ID: 30097 Coppermine Photo Gallery picmgr.php aid Parameter SQL Injection Source: BID Type: Exploit 20774 Source: CCN Type: BID-20774 Coppermine Photo Gallery Picmgr.PHP SQL Injection Vulnerability Source: VUPEN Type: UNKNOWN ADV-2006-4226 Source: XF Type: UNKNOWN coppermine-picmgr-sql-injection(29851) Source: EXPLOIT-DB Type: UNKNOWN 2660 | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |