Vulnerability Name: | CVE-2008-1840 (CCN-41784) | ||||||||
Assigned: | 2008-04-11 | ||||||||
Published: | 2008-04-11 | ||||||||
Updated: | 2017-08-08 | ||||||||
Summary: | SQL injection vulnerability in upload.php in Coppermine Photo Gallery (CPG) 1.4.16 and earlier allows remote authenticated users or user-assisted remote HTTP servers to execute arbitrary SQL commands via the Content-Type HTTP response header provided by the HTTP server that is used for an upload. | ||||||||
CVSS v3 Severity: | 5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L)
| ||||||||
CVSS v2 Severity: | 6.5 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P) 5.7 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
5.7 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P/E:H/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-89 | ||||||||
Vulnerability Consequences: | Data Manipulation | ||||||||
References: | Source: CCN Type: Coppermine Photo Gallery Web site Coppermine Photo Gallery Source: MITRE Type: CNA CVE-2008-1840 Source: CCN Type: Coppermine Gallery Forum, April 11, 2008, 12:17:55 AM cpg1.4.17 Security release - upgrade absolutely mandatory! Source: CONFIRM Type: Exploit http://forum.coppermine-gallery.net/index.php/topic,51787,0.html Source: CCN Type: SA29795 Coppermine Photo Gallery "upload.php" SQL Injection Source: SECUNIA Type: Vendor Advisory 29795 Source: CCN Type: SourceForge.net: Files Coppermine Photo Gallery Source: CONFIRM Type: Patch http://sourceforge.net/project/shownotes.php?group_id=89658&release_id=592069 Source: OSVDB Type: UNKNOWN 44345 Source: CCN Type: OSVDB ID: 44341 Coppermine Photo Gallery bridge/coppermine.inc.php Bridge Wizard Session Cookie SQL Injection Source: CCN Type: OSVDB ID: 44345 Coppermine Photo Gallery upload.php Content-Type HTTP Header SQL Injection Source: BID Type: Patch 28766 Source: CCN Type: BID-28766 Coppermine Photo Gallery 'upload.php' SQL Injection Vulnerability Source: XF Type: UNKNOWN coppermine-upload-sql-injection(41784) Source: XF Type: UNKNOWN coppermine-upload-sql-injection(41784) | ||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||
BACK |