Vulnerability Name: | CVE-2007-0836 (CCN-32233) | ||||||||
Assigned: | 2007-02-05 | ||||||||
Published: | 2007-02-05 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | admin.php in Coppermine Photo Gallery 1.4.10, and possibly earlier, allows remote authenticated users to include arbitrary local and possibly remote files via the (1) "Path to custom header include" and (2) "Path to custom footer include" form fields. Note: The provenance of this information is unknown; the details are obtained solely from third party information. | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N) 3.2 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N/E:U/RL:U/RC:UR)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:U/RL:U/RC:UR)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2007-0836 Source: OSVDB Type: UNKNOWN 33094 Source: CCN Type: SA24019 Coppermine Photo Gallery File Inclusion and Command Execution Source: SECUNIA Type: Vendor Advisory 24019 Source: CCN Type: SourceForge.net Coppermine Photo Gallery Source: CCN Type: OSVDB ID: 33094 Coppermine Photo Gallery admin.php Multiple Custom File Inclusion Field Local File Inclusion Source: BID Type: UNKNOWN 22409 Source: CCN Type: BID-22409 Coppermine Photo Gallery Multiple Remote And Local File Include Vulnerabilities Source: XF Type: UNKNOWN coppermine-admin-file-include(32233) Source: XF Type: UNKNOWN coppermine-admin-file-include(32233) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |