Vulnerability Name: | CVE-2007-0115 (CCN-31388) | ||||||||
Assigned: | 2007-01-05 | ||||||||
Published: | 2007-01-05 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | Static code injection vulnerability in Coppermine Photo Gallery 1.4.10 and earlier allows remote authenticated administrators to execute arbitrary PHP code via the Username to login.php, which is injected into an error message in security.log.php, which can then be accessed using viewlog.php. | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.0 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P) 5.4 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P/E:F/RL:U/RC:UR)
5.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:F/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MISC Type: Exploit http://acid-root.new.fr/poc/19070104.txt Source: CCN Type: BugTraq Mailing List, Fri Jan 05 2007 - 05:34:11 CST Coppermine Photo Gallery <= 1.4.10 SQL Injection Exploit Source: CCN Type: Coppermine Photo Gallery Web site Coppermine Download Maintenance Release Source: MITRE Type: CNA CVE-2007-0115 Source: OSVDB Type: UNKNOWN 33383 Source: SREASON Type: UNKNOWN 2107 Source: VIM Type: Exploit 20070108 Source verify - Coppermine Photo Gallery <= 1.4.10 code injection Source: CCN Type: OSVDB ID: 33383 Coppermine Photo Gallery login.php Username Parameter SQL Injection Source: BUGTRAQ Type: UNKNOWN 20070105 Coppermine Photo Gallery <= 1.4.10 SQL Injection Exploit Source: XF Type: UNKNOWN coppermine-login-code-execution(31388) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |