3.5
CVSSv2

CVE-2007-4977

Published: 19/09/2007 Updated: 15/10/2018
CVSS v2 Base Score: 3.5 | Impact Score: 2.9 | Exploitability Score: 6.8
VMScore: 355
Vector: AV:N/AC:M/Au:S/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in mode.php in Coppermine Photo Gallery (CPG) 1.4.12 and previous versions allows remote malicious users to inject arbitrary web script or HTML via the referer parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

coppermine coppermine photo gallery 1.4.10

coppermine coppermine photo gallery 1.4.11

coppermine coppermine photo gallery 1.4.12

coppermine coppermine photo gallery 1.4.2

coppermine coppermine photo gallery 1.4

coppermine coppermine photo gallery 1.4.4

coppermine coppermine photo gallery 1.4.9

Exploits

source: wwwsecurityfocuscom/bid/25698/info Coppermine Photo Gallery is prone to a cross-site scripting issue and a local file-include issue Attackers can exploit these issues to steal cookie-based authentication credentials, execute arbitrary code, and retrieve arbitrary content within the context of the webserver process Coppermine P ...