6.5
CVSSv2

CVE-2007-4976

Published: 19/09/2007 Updated: 15/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in viewlog.php in Coppermine Photo Gallery (CPG) 1.4.12 and previous versions allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the log parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

coppermine coppermine photo gallery 1.4.10

coppermine coppermine photo gallery 1.4.11

coppermine coppermine photo gallery 1.4.12

coppermine coppermine photo gallery 1.4.2

coppermine coppermine photo gallery 1.4

coppermine coppermine photo gallery 1.4.4

coppermine coppermine photo gallery 1.4.9

Exploits

source: wwwsecurityfocuscom/bid/25698/info Coppermine Photo Gallery is prone to a cross-site scripting issue and a local file-include issue Attackers can exploit these issues to steal cookie-based authentication credentials, execute arbitrary code, and retrieve arbitrary content within the context of the webserver process Coppermin ...