Vulnerability Name: | CVE-2008-0506 (CCN-40058) | ||||||||
Assigned: | 2008-01-29 | ||||||||
Published: | 2008-01-29 | ||||||||
Updated: | 2018-10-15 | ||||||||
Summary: | include/imageObjectIM.class.php in Coppermine Photo Gallery (CPG) before 1.4.15, when the ImageMagick picture processing method is configured, allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) quality, (2) angle, or (3) clipval parameter to picEditor.php. | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P) 5.6 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P/E:F/RL:OF/RC:C)
5.4 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:F/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: CCN Type: Coppermine Photo Gallery Web site Coppermine Photo Gallery Source: CCN Type: Coppermine Forum, Janauary 29, 2008, 08:35:42 AM Maintenance release cpg1.4.15 (security-related) - upgrade mandatory Source: CONFIRM Type: Patch http://coppermine-gallery.net/forum/index.php?topic=50103.0 Source: MITRE Type: CNA CVE-2008-0506 Source: CCN Type: SA28682 Coppermine Photo Gallery Multiple Vulnerabilities Source: SECUNIA Type: Vendor Advisory 28682 Source: CCN Type: SECTRACK ID: 1019286 Coppermine Photo Gallery Input Validation Flaw in 'imageObjectIM' Lets Remote Users Execute Arbitrary Commands Source: CCN Type: OSVDB ID: 41676 Coppermine Photo Gallery include/imageObjectIM.class.php Multiple Parameter Remote Command Execution Source: BUGTRAQ Type: UNKNOWN 20080130 [waraxe-2008-SA#065] - Remote Shell Command Execution in Coppermine 1.4.14 Source: BID Type: Exploit, Patch 27512 Source: CCN Type: BID-27512 Coppermine Photo Gallery Multiple Remote Command Execution Vulnerabilities Source: SECTRACK Type: UNKNOWN 1019286 Source: VUPEN Type: Vendor Advisory ADV-2008-0367 Source: MISC Type: UNKNOWN http://www.waraxe.us/advisory-65.html Source: XF Type: UNKNOWN copperminephoto-class-command-execution(40058) Source: EXPLOIT-DB Type: UNKNOWN 5019 Source: CCN Type: Rapid7 Vulnerability and Exploit Database [01-30-2008] Coppermine Photo Gallery picEditor.php Command Execution | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |